System for tracing use of electronic content by end user
Abstract
Problem to be solved.To provide a system for tracking the use of digital contents on a user device. An electronic store coupled to a network sells a license to reproduce digital content data to a user. A content player who receives the licensed content data from the network is used to play the licensed content data. The logging site receives playback information from the network that includes the number of times the content data has been played by the associated content player. In addition, whenever the content data is played by the content player or when the content data is copied from the content player to an external medium, the information is sent to the logging site and, as a result, licensed. You will be able to track the use of content data. [Selection diagram] Fig. 2

Term
Term ended
Projected expiry passed 10 September 2024, 2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
51 claims: 11 independent, 40 dependent
- 1格納装置上に格納されたディジタル・コンテンツ・データを再生するための且つ前記ディジタル・コンテンツに関連する使用情報をリモート・サイトに提供するためのディジタル・コンテンツ・データ・プレイヤであって、 格納装置に接続するためのインタフェースと、 第1の暗号化鍵で暗号化されているところの予め暗号化されたディジタル・コンテンツ・データを受信するための受信装置であって、前記受信装置は、前記ディジタル・コンテンツ・プレイヤからの暗号化鍵で暗号化されているところの暗号化された第1の復号化鍵をクリアリングハウスから受信する、前記受信装置と、 前記ディジタル・コンテンツ・プレイヤからの復号化鍵で第1の復号化鍵を復号化するための耐タンパ環境であって、前記耐タンパ環境は、ディジタル・コンテンツ・プレイヤを暗号化する局所的に生成された鍵で前記ディジタル・コンテンツ・データを再暗号化することによって、再暗号化されたディジタル・コンテンツ・データを形成し、前記予め暗号化されたディジタル・コンテンツは前記第1の復号化鍵で復号化されており、及び前記耐タンパ環境は前記格納装置上に前記再暗号化されたディジタル・コンテンツを格納する、耐タンパ環境と、 前記格納された再暗号化されたディジタル・コンテンツ・データを復号化し且つ再生するための、及び再暗号化されたディジタル・コンテンツを表す使用情報を生成するための、前記インタフェースに結合されたプレイヤと、 前記使用情報をリモート・ロギング・サイトに転送するための送信機であって、前記使用情報は、前記再暗号化されたディジタル・コンテンツ・データの前記プレイヤによる再生及び前記格納装置から外部記録媒体への前記再暗号化されたディジタル・コンテンツ・データの少なくとも一部分のコピーどりのうちの少なくとも一つを前記遠隔ロギング・サイトに知らせる、前記送信機と を含む、前記ディジタル・コンテンツ・データ・プレイヤ
- 2前記受信機が、予め暗号化されたディジタル・コンテンツ・データをディジタル・コンテンツホストから受信する、請求項1に記載のディジタル・コンテンツ・データ・プレイヤ。
- 3前記格納装置が、ハードディスク、リムーバルディスク、フラッシュ・メモリ、及び光ディスクの内の一つである、請求項1に記載のディジタル・コンテンツ・データ・プレイヤ。
- 4前記外部記録媒体が、コンパクトディスク、DVDディスク、ミニディスク、フラッシュ・メモリ、及びディジタルテープのうちの一つである、請求項1に記載のディジタル・コンテンツ・データ・プレイヤ。
- 5前記予め暗号化されたディジタル・コンテンツ・データが、ディジタル音楽データを含む、請求項1に記載のディジタル・コンテンツ・データ・プレイヤ。
- 6前記使用情報が、最後に前記再暗号化されたディジタル・コンテンツが再生されたことを含む、請求項1に記載のディジタル・コンテンツ・データ・プレイヤ。
- 7前記使用情報が、前記データ・プレイヤ上で前記再暗号化されたディジタル・コンテンツを再生する前記ユーザの識別を含む、請求項1に記載のディジタル・コンテンツ・データ・プレイヤ。
- 8ディジタル・コンテンツ・プレイヤ上でのディジタル・コンテンツの使用を遠隔的に追跡するためのシステムであって、 ディジタル・コンテンツ・データを再生するためにライセンスをユーザに承認するための複数の電子商店システムであって、各電子商店システムはネットワークに接続されている、前記電子商店システムと、 コンテンツ・データを再生するための複数のディジタル・コンテンツ・プレイヤと、 を含み、 各ディジタル・コンテンツ・プレイヤは、 ユーザの一人によってライセンスされた予め暗号化されたディジタル・コンテンツ・データを前記ネットワークから受信する受信装置であって、前記予め暗号化されたディジタル・コンテンツ・データは、第1の暗号化鍵で暗号化されており、前記受信機は、前記ディジタル・コンテンツ・プレイヤからの暗号化鍵で暗号化されている第1の復号化鍵をクリアリングハウスから受信する、前記受信装置と、 前記ディジタル・コンテンツ・プレイヤからの復号化鍵で前記第1の復号化鍵を復号化するための耐タンパ環境であって、前記耐タンパ環境は、ディジタル・コンテンツ・プレイヤを暗号化する局所的に生成された鍵で前記ディジタル・コンテンツ・データを再暗号化することによって再暗号化されたディジタル・コンテンツ・データを形成し、前記予め暗号化されたディジタル・コンテンツは前記第1の復号化鍵で復号化されている、前記耐タンパ環境と、 前記再暗号化されたディジタル・コンテンツ・データの再生を追跡するための前記ネットワークに結合された遠隔ロギング・サイトと を含み、 前記遠隔ロギング・サイトは、前記ディジタル・コンテンツ・プレイヤの夫々からの再生情報を前記ネットワークから受信し、前記各ディジタル・コンテンツ・プレイヤのための前記再生情報は、前記再暗号化されたディジタル・コンテンツ・データが前記ディジタル・コンテンツ・プレイヤによって再生された回数を含む、前記システム。
- 9前記予め暗号化されたディジタル・コンテンツ・データがディジタル音楽データを含む、請求項8に記載の方法。
- 10前記ネットワークに結合されたディジタルコンテンツ・サイトをさらに含み、前記ディジタルコンテンツ・サイトは、前記予め暗号化されたディジタル・コンテンツ・データを前記ディジタル・コンテンツ・プレイヤに送信する、請求項8に記載の方法。
- 11前記再生情報が、前記再暗号化されたディジタル・コンテンツが再生されている最後の時間をまた含む、請求項8に記載の方法。
- 12前記再生情報が、前記コンテンツプレイヤ上で前記再暗号化されたディジタル・コンテンツを再生するユーザの識別をまた含む、請求項8に記載の方法。
- 13前記ディジタル・コンテンツ・プレイヤの一つが、前記再暗号化されたディジタル・コンテンツ・データを再生するたびに、前記ロギング・サイトが前記1つのディジタル・コンテンツ・プレイヤからの前記再生情報を受信する、請求項8に記載の方法。
- 14ディジタル・コンテンツ・プレイヤ上でのディジタル・コンテンツの使用を遠隔的に追跡する方法であって、 ディジタル・コンテンツ・プレイヤ上でユーザに対してディジタル・コンテンツ・データを再生するためのライセンスを承認するステップと、 予め暗号化されたディジタル・コンテンツ・データを前記ライセンスの条件の下で受け入れるステップであって、前記予め暗号化されたディジタル・コンテンツは第1の暗号化鍵で暗号化されている、前記受け入れるステップと、 前記ディジタル・コンテンツ・プレイヤからの暗号化鍵で暗号化されている第1の復号化鍵をクリアリングハウスから受信するするステップと、 耐タンパ環境において、前記ディジタル・コンテンツ・プレイヤからの復号化鍵で前記第1の復号化鍵を復号化するステップと、 ディジタル・コンテンツ・プレイヤを暗号化する局所的に生成された鍵で前記ディジタル・コンテンツ・データを再暗号化することによって再暗号化されたディジタル・コンテンツ・データを形成するステップであって、前記予め暗号化されたディジタル・コンテンツは前記第1の復号化鍵により復号化されている、前記形成するステップと、 前記再暗号化されたディジタル・コンテンツ・データの使用が追跡されうるように、前記再暗号化されたディジタル・コンテンツ・データが、前記ディジタル・コンテンツ・プレイヤによって再生される及び前記ディジタル・コンテンツ・プレイヤから外部媒体にコピーされるのうちの少なくとも1つであるたびに、情報を遠隔ロギング・サイトに転送するステップと、 を含む、前記方法。
- 15前記再暗号化されたディジタル・コンテンツ・データを復号化及び再生するステップをさらに含む、請求項14に記載の方法。
- 16電子取引ホストによって前記ユーザにライセンスを付与するステップをさらに含む、請求項14に記載の方法。
- 17前記再暗号化されたディジタル・コンテンツ・データをハードディスク、フラッシュ・メモリ、リムーバブルディスク、及び光ディスクの少なくとも1つ上で格納するステップをさらに含む、請求項16に記載の方法。
- 18前記再暗号化されたディジタル・コンテンツ・データを外部媒体にコピーするステップであって、前記外部記録媒体が、コンパクトディスク、DVDディスク、ミニディスク、フラッシュ・メモリ、及びディジタルテープのうちの一つである、前記コピーするステップと、 前記再暗号化されたディジタル・コンテンツ・データが前記ディジタル・コンテンツ・プレイヤから前記外部記録媒体にコピーするたびに前記ロギング・サイトに情報を転送するステップと をさらに含む、請求項17に記載の方法。
- 19前記予め暗号化されたディジタル・コンテンツ・データが、ディジタル音楽データを含む、請求項14に記載の方法。
- 20前記転送された情報が、前記再暗号化されたディジタル・コンテンツが再生されている最後の時間を含む、請求項14に記載の方法。
- 21前記転送された情報が、前記コンテンツ・プレイヤ上で前記再暗号化されたディジタル・コンテンツを再生する前記ユーザの識別を含む、請求項14に記載の方法。
- 22ディジタル・コンテンツ・プレイヤ上でのディジタル・コンテンツの使用を遠隔的に追跡する方法であって、 ディジタル・コンテンツ・プレイヤ上でディジタル・コンテンツ・データを再生するためのライセンスを受けるステップと、 前記ライセンスされ予め暗号化されたディジタル・コンテンツ・データを前記ユーザのディジタル・コンテンツ・プレイヤに受信するステップであって、前記予め暗号化されたディジタル・コンテンツは第1の暗号化鍵で暗号化されている、前記受信するステップと、 前記ディジタル・コンテンツ・プレイヤからの暗号化鍵で暗号化されている第1の復号化鍵をクリアリングハウスから受信するするステップと、 耐タンパ環境において、前記ディジタル・コンテンツ・プレイヤからの復号化鍵で前記第1の復号化鍵を復号化するステップと、 ディジタル・コンテンツ・プレイヤを暗号化する局所的に生成された鍵で前記ディジタル・コンテンツ・データを再暗号化することによって再暗号化されたディジタル・コンテンツ・データを形成するステップと、 前記再暗号化されたディジタル・コンテンツ・データが前記ディジタル・コンテンツ・プレイヤによって再生される毎に、前記ディジタル・コンテンツ・プレイヤ中に再生情報を記録するステップと、 前記記録された再生情報を所定の時刻に又は所定の間隔で遠隔のロギング・サイトに送信して、前記再暗号化されたディジタル・コンテンツ・データの使用を追跡することを可能にするステップと を含む、前記方法。
- 23前記ライセンスは、電子商業ホストによってユーザに与えられる、前記22に記載の方法。
- 24前記再暗号化されたディジタル・コンテンツ・データをハードディスク、フラッシュ・メモリ、リムーバブルディスク、及び光ディスクの少なくとも1つ上で格納するステップをさらに含む、請求項22記載の方法。
- 25前記再暗号化されたディジタル・コンテンツ・データをコンパクトディスク、DVDディスク、ミニディスク、フラッシュ・メモリ、及びディジタルテープのうちの一つにコピーするステップと、 前記再暗号化されたディジタル・コンテンツ・データが前記ディジタル・コンテンツ・プレイヤによって再生される毎に、前記ディジタル・コンテンツ・プレイヤ中にコピー情報を記録するステップと、 前記記録されたコピー情報を所定の時間で又は所定の間隔でロギング・サイトに送信するステップと をさらに含む、請求項23に記載の方法。
- 26前記再暗号化されたディジタル・コンテンツ・データはディジタル音楽データを含む、請求項22に記載の方法。
- 27前記再生情報は、前記再暗号化されたディジタル・コンテンツが再生されている最後の時間を含む、請求項14に記載の方法。
- 28前記再生情報は、前記コンテンツプレイヤ上で前記再暗号化されたディジタル・コンテンツを再生するユーザの識別を含む、請求項22に記載の方法。
- 29ディジタル・コンテンツ・プレイヤ上でのディジタル・コンテンツの使用を遠隔的に追跡する方法であって、 複数のユーザに対してディジタル・コンテンツ・データを再生するためにライセンスを承認するステップと、 それぞれのユーザについて、予め暗号化されたディジタル・コンテンツ・データを前記ユーザのディジタル・コンテンツ・プレイヤに送信するステップであって、前記予め暗号化されたディジタル・コンテンツは第1の暗号化鍵で暗号化されている、前記送信するステップと、 前記ディジタル・コンテンツ・プレイヤからの暗号化鍵で暗号化されている第1の復号化鍵をクリアリングハウスから受信するするステップと、 耐タンパ環境において、前記ディジタル・コンテンツ・プレイヤからの復号化鍵で前記第1の復号化鍵を復号化するステップと、 ディジタル・コンテンツ・プレイヤを暗号化する局所的に生成された鍵で前記ディジタル・コンテンツ・データを再暗号化することによって再暗号化されたディジタル・コンテンツ・データを形成するステップと、 前記ディジタル・コンテンツ・プレイヤの夫々からの再生情報を遠隔ロギング・サイトに送信するステップであって、前記再暗号化されたディジタル・コンテンツ・データの使用を追跡することを可能にするために、前記再生情報は前記再暗号化されたディジタル・コンテンツ・データが各ユーザによって再生された時間の回数を含む、前記送信するステップと を含む、前記方法。
- 30前記再生情報を所定の時間で又は所定の間隔で前記ロギング・サイトに送信するステップをさらに含む、請求子29に記載の方法。
- 31前記ライセンスが電子商業ホストによって承認される、請求項30に記載の方法。
- 32前記再暗号化されたディジタル・コンテンツ・データをハードディスク、リムーバルディスク、及び光ディスクの少なくとも1つに記録するステップをさらに含む、請求項30に記載の方法。
- 33前記再生情報を受信する遠隔ロギング・サイトに前記再生情報を送信するステップが、前記再暗号化されたディジタル・コンテンツ・データが各ユーザによって外部メディアにコピーされている時間の数を送信するステップを更に含む、請求項30に記載の方法。
- 34前記予め暗号化されたディジタル・コンテンツ・データが、ディジタル音楽データを含む、請求項30に記載の方法。
- 35前記再生情報が、前記再暗号化されたディジタル・コンテンツが再生されている最後の時間を含む、請求項30に記載の方法。
- 36前記再生情報が、前記コンテンツプレイヤ上で前記再暗号化されたディジタル・コンテンツを再生する前記ユーザの識別を含む、請求項30に記載の方法。
- 37ディジタル・コンテンツ・プレイヤ上でのディジタル・コンテンツの使用を遠隔的に追跡するプログラムを記録したコンピュータ読み取り可能記録媒体であって、 ディジタル・コンテンツ・プレイヤ上でユーザに対してディジタル・コンテンツ・データを再生するためにライセンスを承認するステップと、 予め暗号化されたディジタル・コンテンツ・データを前記ライセンスの条件の下で受け入れるステップであって、前記予め暗号化されたディジタル・コンテンツは第1の暗号化鍵で暗号化されている、前記受け入れるステップと、 前記ディジタル・コンテンツ・プレイヤからの暗号化鍵で暗号化されている第1の復号化鍵をクリアリングハウスから受信するするステップと、 耐タンパ環境において、前記ディジタル・コンテンツ・プレイヤからの復号化鍵で前記第1の復号化鍵を復号化するステップと、 ディジタル・コンテンツ・プレイヤを暗号化する局所的に生成された鍵で前記ディジタル・コンテンツ・データを再暗号化することによって再暗号化されたディジタル・コンテンツ・データを形成するステップであって、前記予め暗号化されたディジタル・コンテンツは前記第1の復号化鍵により復号化されている、前記形成するステップと、 前記再暗号化されたディジタル・コンテンツ・データの使用が追跡されうるように、前記再暗号化されたディジタル・コンテンツ・データが、前記ディジタル・コンテンツ・プレイヤによって再生される及び前記ディジタル・コンテンツ・プレイヤから外部媒体にコピーされるのうちの少なくとも1つであるたびに、情報を遠隔ロギング・サイトに転送するステップと、 を含むプログラムを記録したコンピュータ読み取り可能記録媒体。
- 38前記再暗号化されたディジタル・コンテンツ・データを復号化及び再生するステップをさらに含むプログラムを記録した請求項37に記載のコンピュータ読み取り可能記録媒体。
- 39電子取引ホストによって前記ユーザにライセンスを付与するステップをさらに含むプログラムを記録した請求項37に記載のコンピュータ読み取り可能記録媒体。
- 40前記再暗号化されたディジタル・コンテンツ・データをハードディスク、フラッシュ・メモリ、リムーバブルディスク、及び光ディスクの少なくとも1つ上で格納するステップをさらに含むプログラムを記録した請求項37に記載のコンピュータ読み取り可能記録媒体。
- 41前記再暗号化されたディジタル・コンテンツ・データを外部媒体にコピーするステップであって、前記外部記録媒体が、コンパクトディスク、DVDディスク、ミニディスク、フラッシュ・メモリ、及びディジタルテープのうちの一つである、前記コピーするステップと、 前記再暗号化されたディジタル・コンテンツ・データが前記ディジタル・コンテンツ・プレイヤから前記外部記録媒体にコピーするたびに前記ロギング・サイトに情報を転送するステップと をさらに含むプログラムを記録した請求項40に記載のコンピュータ読み取り可能記録媒体。
- 42前記予め暗号化されたディジタル・コンテンツ・データが、ディジタル音楽データを含むプログラムを記録した請求項37に記載のコンピュータ読み取り可能記録媒体。
- 43前記転送された情報が、前記再暗号化されたディジタル・コンテンツが再生されている最後の時間を含むプログラムを記録した請求項37に記載のコンピュータ読み取り可能記録媒体。
- 44前記転送された情報が、前記コンテンツ・プレイヤ上で前記再暗号化されたディジタル・コンテンツを再生する前記ユーザの識別を含むプログラムを記録した請求項37に記載のコンピュータ読み取り可能記録媒体。
- 45ディジタル・コンテンツ・データを再生するディジタル・コンテンツ・データ・プレイヤであって、前記データ・プレイヤが、使用情報を送信する送信器を含み、前記使用情報が、前記ディジタル・コンテンツ・データの再正またはコピーの発生、前記ディジタル・コンテンツ・データが再正またはコピーされた回数、前記ディジタル・コンテンツ・データが再正またはコピーされた時、および前記ディジタル・コンテンツ・データを再正またはコピーしたユーザの識別のうちの少なくとも1つである、ディジタル・コンテンツ・データ・プレイヤ。
- 46前記ディジタル・コンテンツ・データが、ディジタル音楽データを含む、請求項45に記載のデータ・プレイヤ。
- 47ディジタル・コンテンツの使用を追跡するシステムであって、 ディジタル・コンテンツ・データを再正またはコピーするライセンスと、 ライセンスを交付されたディジタル・コンテンツ・データと、 前記ライセンスを交付されたディジタル・コンテンツ・データの再正またはコピーの発生、前記ライセンスを交付されたディジタル・コンテンツ・データが再正またはコピーされた回数、前記ライセンスを交付されたディジタル・コンテンツ・データが再正またはコピーされた時、および前記ライセンスを交付されたディジタル・コンテンツ・データを再正またはコピーしたユーザの識別のうちの少なくとも1つに関する情報と を含むシステム。
- 48前記情報に基づいて、それ以上の再正またはコピーを禁止することをさらに含む、請求項47に記載のシステム。
- 49前記ディジタル・コンテンツ・データが、ディジタル音楽データを含む、請求項47に記載のシステム。
- 50前記情報が、所定の時刻にまたは所定の間隔で送信される、請求項47に記載のシステム。
- 51ユーザ装置上でのディジタル・コンテンツ・データの使用を追跡する命令を記録したコンピュータ読み取り可能な記録媒体であって、 ディジタル・コンテンツ・データを再正またはコピーするライセンスを得る命令と、 前記ライセンス交付されたディジタル・コンテンツを受け入れる命令と、 前記ディジタル・コンテンツ・データの再生、前記ディジタル・コンテンツ・データのコピー、前記ディジタル・コンテンツ・データが再正またはコピーされた時、および前記ディジタル・コンテンツ・データを再正またはコピーしたユーザの識別のうちの少なくとも1つにに関する情報を送信する命令と を記録したコンピュータ読み取り可能な記録媒体。
Independent claims51
388 paragraphs, as filed
The disclosed inventions broadly relate to the field of electronic commerce, specifically via global communication networks such as the Internet and the World Wide Web for digital assets such as print media, films, games, and music. For systems and related tools for secure distribution and rights management.
The use of global distribution systems such as the Internet to distribute digital assets such as music, films, computer programs, pictures, games, and other content continues to grow. At the same time, owners and publishers of valuable digital content have been slow to adopt the use of the Internet for the distribution of digital assets for several reasons. One reason is that owners are afraid of unauthorized copying or piracy of digital content. Electronic distribution of digital content removes multiple barriers to piracy. One of the barriers removed by electronic distribution is the need for tangible recordable media themselves (eg diskettes or CD-ROMs). Copying digital content to tangible media often costs less than $ 1 for blank tapes or recordable CDs. However, in the case of electronic distribution, tangible media is no longer needed. Since the content is distributed electronically, the cost of tangible media is no longer a factor. The second barrier is the format of the content itself, that is, the contrast between the content stored in analog format and the content stored in digital format. Content stored in analog format, such as printed pictures, is of lower quality than the original when reproduced by photocopying. Each subsequent copy of a copy may be referred to as a generation, but each generation is inferior in quality to the original. This quality degradation does not exist when the picture is stored digitally. Each copy and all generations of copy can be as clear and fresh as the original. The combined effect of fully digital copying combined with the very low cost of electronic content distribution and widespread content distribution over the Internet makes the distribution of piracy and unauthorized copies considerably easier. With just a few keystrokes, pirates inject a complete copy of hundreds or thousands of digital content. It can be sent via the internet. Therefore, there is a need to ensure the protection and security of electronically distributed digital assets.
Digital content providers want to establish a protected global distribution system for digital content that protects the rights of content owners. Issues associated with establishing digital content distribution systems include developing systems for digital content electronic distribution, rights management, and asset protection. Electronically distributed digital content includes content such as print media, films, games, programs, television, multimedia, and music.
The deployment of electronic distribution systems gives digital content providers the ability to achieve immediate sales reporting and quick settlement of payments through electronic adjustments, as well as the ability to obtain a secondary source of revenue through content redistribution. .. Electronic digital content distribution systems are not affected by physical inventory shortages or returns, allowing digital content providers and retailers to achieve cost savings and improved gross margins. Digital content providers can promote new distribution channels or augment existing distribution channels for better time-limited inventory releases. Transaxin data from electronic distribution systems can be used to obtain information about consumer purchasing patterns and to provide immediate feedback on electronic marketing programs and promotions. To meet these goals, digital content providers use an electronic distribution model that ensures the protection and measurement of digital assets while making digital content available to a wide range of users and companies. There is a need.
real audio, AT & T's A2B, LiquidAudioPro Corp.'s Liquid Audio Pro, AudioSoft's CityMusic Other commercial electronic distribution systems for digital content, such as Networks and others, provide the transmission of digital data over protected and unprotected electronic networks. The use of protected electronic networks significantly reduces the digital content provider's requirement to distribute digital content to a wide audience. Unprotected networks such as the Internet and the Web allow digital content to reach end users in a protected manner, such as through the use of cryptography. However, once the encrypted digital content has been decrypted on the end user's computer, the digital content becomes readily available to the end user for unauthorized redistribution. Therefore, a secure digital content electronic distribution system that provides protection for digital assets and ensures that the rights of content providers are protected even after the digital content has been distributed to consumers and companies. There is a need. Therefore, there is a need for rights management that allows secure distribution, licensing, and control of digital asset usage.
Another reason digital content owners have been late in adopting electronic distribution is that they want to maintain and nurture existing distribution channels. Most content owners sell through retailers. In the music market, these US retailers include Tower Records, Peaches, Blockbuster, Circuit City and others. Many of these retailers have websites that allow Internet users to make choices over the Internet and have their end users email their choices. Examples of music websites include ower, MusicBoulevard, and Columbia House. Electronic distribution can deprive retailers of their ability to differentiate themselves from each other and content owners to differentiate themselves, especially on the Web. Therefore, there is a need to provide retailers of electronic content such as pictures, games, music, programs, and videos with a way to differentiate themselves from each other and from content owners when selling music through electronic distribution. To do.
Content owners prepare digital content for electronic distribution through distribution sites such as electronic stores. Electronic stores on the Internet or through other online services seek to differentiate themselves from each other through product offerings and product promotions. Traditional stores, ie, non-electronic, non-online e-shop analogs, discriminate themselves from competitors using product promotions, product sales, product samples, generous return policies, and other promotional programs. To become. However, in the online world where content providers impose terms of use for digital content, the ability of electronic stores to differentiate themselves can be severely limited. In addition, electronic stores process metadata related to digital content from content providers in order to promote and sell their products electronically, even if the terms of use can be changed. Face the difficult task. Electronic stores need to manage multiple requirements when processing metadata. First, electronic stores need to receive metadata related to digital content from content providers. In many cases, some of this metadata may be sent encrypted, so content providers must create a mechanism to decrypt the encrypted content. Second, e-shops support product marketing, product positioning, and other promotional considerations regarding content, either before the e-shop receives the content from the content provider or after the e-shop receives the content. You may want to preview the metadata from your content provider to do so. Third, electronic stores need to extract some metadata used for promotional materials such as graphics and artist information. Often, this promotional material is used directly by electronic stores for their online promotions. Fourth, electronic stores allow You may want to differentiate yourself from each other by modifying some of the terms of use that have been made to create different offerings of digital content. Fifth, the e-shop inserts an address such as a URL in the metadata to automatically direct the payment adjustment to the accounting reconciliation company by the buyer without having to go through the e-shop to clear the payment. May need to be changed. Sixth, e-shops may need to create licenses for the permitted use of copyrighted digital content that matches the terms of use. For example, this license can grant permission to make a limited number of copies of digital content. A license is required to reflect the duration and terms of the grant granted.
In view of all of these requirements, in order to process metadata related to digital content, many e-shops create customized software programs to handle these requirements. The time, cost, and testing required to create these customized software programs can be significant. Therefore, there is a need to provide a solution to these requirements.
In addition, another reason digital content owners have been late in adopting electronic distribution is the difficulty of preparing content for electronic distribution. Today, many content providers have thousands or tens of thousands of titles in their collections. In the music example, it is not uncommon for content owners to have a single master sound recording available in multiple different formats (eg CDs, tapes, and minidiscs) at the same time. In addition, a single format may have master sound recordings that have been remastered or remixed for a particular distribution channel. As an example, mixing for radio broadcasts may differ from mixing for dance club soundtracks, which may differ from commonly available consumer CDs. Inventory management and recording of these different mixes can be a burden. In addition, many master recording owners make old recordings in various subsequent collections, such as "Best of ~," or in film score soundtrack edits or other collections or edits. Often reissued. As more content is provided digitally, more content needs to be remixed and encoded for electronic distribution. Providers often need to use older recording formats as a guide to choosing the correct master sound recording, and reprocess these sound recordings for publication for electronic distribution. And encode. This can be especially true for content providers who want to use the old format to assist in republishing old sound recordings for electronic distribution. The provider examines the database, matches titles, artists, and sound recordings, and sets coding parameters. This place to manually search the database of recording collections The reason is not without its weaknesses. One of the disadvantages is that the operator must manually search the database and set the processing parameters appropriately. Another disadvantage is the possibility of operator transcription errors when selecting data from the database. Therefore, there is a need to provide content providers with a way to automatically retrieve relevant data and master recordings for content such as audio.
Content owners prepare digital content for electronic distribution through a process called coding. Coding involves taking the content, digitizing it if presented in analog format, and compressing the content. The processing of compression reduces the amount of data transmitted or stored, allowing digital content to be more efficiently transmitted over the network and stored on recordable media. However, compression is not without its drawbacks. Most compressions are called Rossii compressions, with some loss of information. The content provider must decide which compression algorithm to use and which compression level is required. For example, in music, digital content or songs can have very different characteristics depending on the genre of music. The compression algorithm and compression level selected for one genre may not be the best choice for another genre of music. Content providers find that some combinations of compression algorithms and compression levels work very well for one genre of music, for example classical, but with unsatisfactory results for another genre of music, such as heavy metal. You may notice. In addition, the audio engineer must equalize the music, make dynamic range adjustments, and perform other pre-processing and processing settings to ensure that the encoded music genre produces the desired result. Is often. The requirement that coding parameters such as equalization level setting and dynamic range setting must be set manually for each digital content can be burdensome. Returning to the music example, music content providers with collections containing different music genres must manually select the desired combination of encoding parameters for each song or song set to be encoded. Should be. Therefore, manually select the coding processing parameters
The process of compressing content can require a large amount of dedicated computational resources, especially for large content items such as movies without omissions. The compression algorithm provider offers various trade-offs and advantages associated with the compression technique. This trade-off includes the amount of time and computational resources required to compress the content, the amount of compression achieved from the original content, the desired bit rate for playback, the performance quality of the compressed content, and more. Factors are included. The problem is the use of a coding program that takes a multimedia file as input and produces a coded output file with no intermediate representation of progress or status. In addition, in many situations other programs are used to call or manage coding programs that do not have an intermediate representation of progress. This leaves the calling application with no way of indicating the amount of coded content as a percentage of the total selection specified for coding. This can be a problem if the calling program attempts to schedule several different programs to run at the same time. In addition, this can be particularly burdensome if a batch of content is selected for coding and the content provider wants to determine the progress of the coding process. Therefore, there is a need to overcome this problem.
Another reason digital content providers have been slow to adopt electronic distribution for their content is the lack of standards for creating digital players on end-user equipment for electronically distributed content. .. Content providers, e-shops, or others in the e-distribution chain are PCs<sub>S</sub>, Set-top boxes, handheld devices, etc., may want to provide customized players on various devices. You need a set of tools that can handle the decryption of digital content in an anti-tamper environment, that is, an environment that prevents unauthorized access by third parties to the content being played. In addition, there needs to be a set of tools that allow end users to manage local libraries of digital content without being granted access to content for purposes other than those purchased.
Further information on the background of digital content protection can be found from three sources: AT & T Labs, Jack Lacy, James Snyder, David Maher, Florham Park, NJ, USA, available online at the URL http://www.a2bmusic.com/about/papers/musicipp.htm ) Co-authored, "Music on the InternetandtheIntellectual Property Protection Problem". Olin Sibert, David Bernstein, and Wee (Olin Sibert) of InterTrust Technologies Corp. in Sunnyvale, California, USA, available online at the URL http://www.intertrust.com/architecture/stc.html. David Van Wie) co-authored paper, "Securing the Content, Not the Wire for A cryptographically protected container called DigiBox, described in Information Commerce. IBM's white paper "Cryptolope Container Technology" available online at the URL "http:///cyptolope.ibm.com/white.htm".
<p> An object of the present invention is to eliminate the disadvantages mentioned above and to provide a system for tracking the use of content data.</p>
<p> One embodiment of the present invention provides a system for tracking the use of digital content on a user device. A networked e-shop sells licenses to replay digital content data to users. A content player who receives the licensed content data from the network is used to play the licensed content data. In addition, a networked logging site tracks the playback of content data. Specifically, the logging site receives the replay information from the network, and the replay information includes the number of times the content data has been replayed by the associated content player.</p><p> Another embodiment of the invention provides a method of tracking the use of digital content on a user device. According to this method, a license to reproduce the digital content data is sold to the user, and the licensed content data is transmitted to the user's content player. In addition, whenever the content data is played by the content player or when the content data is copied from the content player to an external medium, the information is sent to the logging site and, as a result, licensed. You will be able to track the use of content data.</p>
To help the reader quickly identify different parts of this embodiment, the table of contents of this specification is presented. I. Secure Digital Content Electronic Distribution System A. System Overview 1. Rights Management 2. Measurement 3. Open Architecture B. System Functional Elements 1. Content Provider 2. Electronic Digital Content Store 3. Brokerage Market Partner 4. Clearing house 5. End user equipment 6. Transmission infrastructure C. Use of system II. Cryptographic concept and application to secure digital content electronic distribution system A. Symmetric algorithm B. Public key algorithm C. Digital signature D. Digital Certificate E.SC Graphical Representation F. Example of Secure Container Encryption III. Flow of Secure Digital Content Electronic Distribution System IV. Rights Management Architecture Model A. Architecture Layer Functions B. Functions Classification and flow 1. Content formatting layer 2. Content usage control layer 3. Content identification layer 4. License Control Layer C. Content Distribution and Licensing Control V. Secure Container Structure A. General Structure B. Rights Management Language Syntax and Semantics C. Secure Container Flow and Processing Overview D. Metadata · Format of Secure Container 620 E. Format of Offer Secure Container 641 F. Format of Transaction Secure Container 640 G. Format of Order Secure Container 650 H. Format of License Secure Container 660 I. Content Secure Container Format VI. Secure Container Packing and Unpacking A. Overview B. Material List (BOM) Part C. Key Description Part VII. Clearing House A. Overview B. Rights Management Processing C. Country-Specific Parameters D Audit Logs and Tracking E. Report Results F. Validate Billing and Payments G. Resubmit VIII. Content Providers A. Overview B. Work Flow Manager 1. Action / Information Waiting Product Processing 2. New Content Request processing 3. Automatic metadata acquisition processing 4. Manual metadata input processing 5. Usage condition processing 6. Monitoring and publishing processing 7. Metadata SC creation processing 8. Water marking processing 9. Preprocessing and compression processing 10. Content quality management processing 11 .Encryption processing 12. Content SC creation processing 13. Final quality assurance processing 14. Content distribution processing 15. Work flow rules C. Metadata assimilation and input tool 1. Automatic metadata acquisition tool 2. Manual metadata input tool 3. Terms of Use Tool 4. Metadata SC Parts 5. Monitoring and Publishing Tool D. Content Processing Tool 1. Watermarking Tool 2. Preprocessing and Compression Tool 3. Content Quality Control Tool 4. Encryption Tool E. Content SC Creation Tool F. Final Quality Assurance Tool G. Content Distribution Tool H. Content Promotion Website I. Content Hosting 1. Content Hosting Site 2. Content hosting site provided by secure digital content electronic distribution system 111IX. Electronic digital content store A. Overview Support for multiple electronic digital content stores B. Two-point electronic digital content distribution service 1 .Integration requirements 2. Content acquisition tool 3. Transaction processing module 4. Notification interface module 5. Accounting adjustment tool C. Broadcast electronic digital content distribution service X. End user equipment A. Overview B. Application installation C. SC processor D. Player Application 1. Overview 2. End User Interface Component 3. Copy / Playback Management Component 4. Decryption 1505, Decompression 1506 and Playback Component 5. Data Management 1502 and Library Access Component 6. Inter-Application Communication Component 7. Various other components 8. General-purpose player
I. Secure Digital Content Electronic Distribution System A. System Overview The Secure Digital Content Electronic Distribution System provides secure distribution and rights management of digital content and content related to digital content to end-user client devices. A technology platform that includes the technology, specifications, tools, and software required for. PC for end-user equipment<sub>S</sub>, Set-top box (IRD), and Internet equipment. These devices may copy the content to external media or portable consumer devices with the permission of the content owner. The term "digital content" or simply "content" refers to information and data stored in digital formats, including pictures, movies, videos, music, programs, multimedia, and games.
The technology platform is licensed with digital content prepared and distributed protected to end-user equipment via two-point infrastructure and broadcast infrastructure (cable, internet, satellite, and wireless, etc.). Specifies how it is delivered and protected from unauthorized copying or playback. In addition, the technology platform architecture enables integration and porting of various technologies such as water marking, compression / coding, encryption, and other security algorithms as they are developed in the future. ..
The basic components of a secure digital content electronic distribution system are (1) rights management to protect the ownership of content owners, (2) transaction measurement for immediate and accurate rewards, and (3) standards. Open and clearly documented, allowing content providers to prepare content for playback on all player-compliant players and allow protected delivery over multiple network infrastructures. It is a digital architecture.
1. Rights management The rights management of a secure digital content electronic distribution system is carried out through a set of functions distributed among the operating components of the system. Its key features are licensing and licensing controls that ensure that content is unlocked only by licensed authorized intermediaries or authorized end users, as well as the number of copies allowed and playback. Includes control and enforcement of content use in accordance with the terms of the purchase or license, such as the number of times, the time interval or period during which the license is valid. A secondary function of rights management is to enable means of identifying the source of unauthorized copies of content to combat piracy.
Grant authorization and licensing control are enforced through the use of clearinghouse entities and secure container (SC) technology. A clearinghouse provides licensing authorization by allowing an intermediary or end user to unlock content after verifying the successful completion of a licensing transaction. Secure containers are used to distribute encrypted content and information between system components. SCs are cryptographic carriers of information or content that use cryptography, digital signatures, and digital certificates to provide protection against unauthorized interception or modification of electronic information and content. SC can also be used to verify the authenticity and integrity of digital content. The advantage of these rights management features is that the electronic digital content distribution infrastructure does not need to be protected or trusted. Therefore, transmission over network infrastructures such as the web and the Internet is possible. This is due to the fact that the content is encrypted within the secure container and its storage and distribution is separated from its unlocking and usage control. Only the user with the decryption key can unlock the encrypted content, and the clearinghouse exposes the decryption key only for the appropriate permitted usage requests. The clearinghouse does not allow fake requests from unknown or unauthorized parties, or requests that do not comply with the terms of use of the content set by the content owner. In addition, if the SC is tampered during transmission, the clearinghouse software determines that the SC's content has been corrupted or forged and rejects the transaction.
Content usage control is made available through the end-user player application 195 running on the end-user device. The application embeds digital code, which defines the number of secondary copies and plays allowed, in every copy of the content. It uses digital water marking technology to generate digital code and hide it from other end-user player application 195 to resist attempts to change it. In an alternative embodiment, the digital code is stored simply as part of the terms of use associated with Content 113. When the digital content 113 is accessed within the compliant end-user device, the end-user player application 195 reads the watermark, inspects usage restrictions, and updates the watermark as needed. If the requested use of the content does not comply with the terms of use, for example, the number of copies has been exhausted, the end user device will not execute the request.
Digital water marking also provides a means of identifying the source of authorized or unauthorized copies of content. The first watermark in the content is embedded by the content owner to identify the content owner, specify copyright information, define a geographic distribution area, and add other relevant information. The second watermark identifies the purchaser (or licensee) of the content and the end-user device, specifies the terms and dates of the purchase or license, and adds other relevant information to the end-user. Embedded in the content on the device.
Watermarks are an integral part of the content and are therefore carried within the copy, regardless of whether the copy was authorized or not. Therefore, digital content always contains information about its source and authorized use, regardless of where the content is and where it came from. You can use this information to combat content abuse.
2. Measurement As part of its rights management function, the clearinghouse keeps a record of all transactions authorized for key exchange through the clearinghouse. This record can be used to grant licenses and measure the original terms of use. Transaction records shall be reported immediately or periodically to the responsible party, such as the content owner or content provider, retailer, or others, to facilitate transaction payments and electronic adjustments for other uses. Can be done.
3. Open Architecture The Secure Digital Content Electronic Distribution System (System) has published specifications and interfaces to promote widespread implementation and acceptance of the System in the market while at the same time protecting the rights of content owners. It is an open architecture that maintains. The flexibility and openness of the system also allows it to evolve over time as various technologies, transmission infrastructures, and equipment are brought to market.
This architecture is open with respect to the nature of the content and its format. Distribution of audio, programs, multimedia, video, or other types of content is supported by this architecture. The content can be in a native format such as linear PCM for digital music, or a format achieved by filtering, compression, or additional preprocessing or coding such as pre-emphasis / de-emphasis or the like. This architecture is open to a variety of cryptographic and water marking techniques. This architecture allows you to choose specific techniques to accept different types and formats of content and to be able to introduce or adopt new technologies as they emerge. This flexibility allows content providers to select and evolve the technologies used for data compression, encryption, and formatting within secure digital content electronic distribution systems.
This architecture is also open to different distribution networks and distribution models. This architecture supports content distribution over slow internet connections or high speed satellite and cable networks and can be used with point-to-point or broadcast models. In addition, this architecture is designed to enable end-user equipment functionality in a wide range of equipment, including low-cost consumer equipment. This flexibility allows content providers and retailers to serve content to intermediaries or end users through a variety of service offerings, allowing users to purchase or license content. Will be able to be played back and recorded on various compliant player devices.
B. Functional Elements of the System With reference to FIGS. 1 to 4, a block diagram showing an outline of the secure digital content electronic distribution system 100 according to the present invention is shown. The Secure Digital Content Electronic Distribution System 100 includes multiple business elements, including end-to-end solutions, which include Content Provider 101 or Digital Content Owner, Electronic Digital Content Store 103. Includes, Mediation Market Partners (not shown), Clearing House 105, Content Hosting Site 111, Transmission Infrastructure 107, and End User Equipment 109. Each of these business elements uses various components of the Secure Digital Content Electronic Distribution System 100. Below is a high-level description of these business elements and system components specifically related to the distribution of electronic content 113.
1. Content Provider 101 Is Content Provider 101 or the Content Owner the owner of the original Content 113 or a wholesaler authorized to package the Independent Content 113 for further distribution? , Both. Content Provider 101 licenses Content 113 to Electronic Digital Content Store 103 or an intermediary market partner (not shown) in return for using its rights directly or in return for content usage fees, usually related to e-commerce revenue. ) Can be delivered. Examples of content providers 101 include Sony, Time-Warner, MTV, IBM, Microsoft, Turner, Fox and others.
Content provider 101 uses the tools provided as part of the secure digital content electronic distribution system 100 to prepare content 113 and related data for distribution. The workflow manager tool 154 schedules the content 113 to be processed and tracks the content 113 as it flows through the various steps of preparing and packaging the content 113 to maintain high quality assurance. The term metadata is used throughout this document to mean data related to Content 113 and, in this embodiment, does not include Content 113 itself. As an example, song metadata can be a song title or song credit, but not a song sound recording. Content 113 should include a sound recording. The metadata assimilation and input tool 161 provides metadata (in the case of music, CD title, artist name, song title, CD art) from the content provider's database 160 or data provided by the content provider in a predetermined format. It is used to extract (information on content 113 such as work and others) and package it for electronic distribution. The metadata assimilation and input tool 161 is also used to enter the terms of use for content 113. The terms of use data can include copy restriction rules, wholesale prices, and all business rules deemed necessary. Watermarking tools are used to hide data in Content 113 that identifies the content owner, processing date, and other relevant data. In an embodiment where the content 113 is audio, an audio preprocessor tool is used to adjust the dynamic characteristics for optimal compression quality or equalize the content 113 or other audio to the content to the desired compression level. Compress 113 and encrypt content 113. These are digital content compression / coding
Encrypted content 113, data or metadata associated with digital content, and encrypted keys are packed into an SC (discussed below) by SC packer tools and content hosted for electronic distribution. · Stored on the site or promotional website. Content hosting sites can reside in multiple locations, including content providers 101 or electronic digital content stores 103 and intermediary market partner (not shown) facilities. Both the content 113 and the key (discussed below) are encrypted and packed into the SC, so that the electronic digital content store 103 or other hosting agent has permission from the clearinghouse and content provider 101. You cannot directly access the decrypted content 113 without notifying.
2. Electronic Digital Content Store 103 Electronic Digital Content Store 103 is the entity that sells Content 113 on the market through a wide range of services or applications, such as theme programming of Content 113 or electronic merchandising of Content 113. Electronic Digital Content Store 103 manages the design, development, business operations, decisions, merchandising, marketing, and sales of its services. An example of an online electronic digital content store 103 is a website that offers electronic downloads of software.
In its service, the electronic digital content store 103 implements some functions of the secure digital content electronic distribution system 100. Electronic Digital Content Store 103 collects information from Content Provider 101, packs content and metadata into additional SCs, and distributes these SCs to consumers or businesses as part of a service or application. Electronic Digital Content Store 103 uses the tools provided by Secure Digital Content Electronic Distribution System 100 to assist in metadata extraction, secondary terms of use, SC packaging, and tracking of electronic content transactions. Secondary Terms of Use data can include retail business offers such as purchase price of Content 113, pay-per-listen price, copy permission and target device type, or time-limited availability limit. ..
The electronic digital content store 103 is responsible for allowing the clearinghouse 105 to expose the decryption key of the content 113 to the customer after completing a valid request for the electronic content 113 from the end user. Electronic Digital Content Stores also allow downloads of SCs containing Content 113. An electronic digital content store may choose to host an SC containing digital content at its local site, use hosting and distribution facilities at another content hosting site, or both. Can be done.
The electronic digital content store can provide customer service regarding questions or problems that end users who use the secure digital content electronic distribution system 100 may have, and the electronic digital content store 103 can provide customer service. , Customer service support can be contracted with Clearinghouse 105.
3. Brokerage Market Partners (not shown) In an alternative embodiment, the Secure Digital Content Electronic Distribution System 100 can be used to supply Content 113 in a protected manner to other companies called Brokerage Market Partners. it can. These partners can include digital content affiliates that distribute content 113 that provide non-electronic services such as television stations or video clubs, radio stations or record clubs. These partners can also include other trusted parties who work with material as part of the production or marketing of sound recordings, such as recording studios, replicators, and producers. These intermediary market partners require permission from the clearinghouse 105 to decipher content 113.
4. Clearinghouse 105 The Clearinghouse 105 provides licensing and record keeping for all transactions related to the sale or permitted use of encrypted content 113 within the SC. When the clearinghouse 105 receives a request for a decryption key for content 113 from an intermediary or end user, it verifies the integrity and authenticity of the information in the request, and the request is an electronic digital content store or content provider. Verify that it is authorized by 101 and that the requested use complies with the terms of use of the content defined by Content Provider 101. After these validations are satisfied, the clearinghouse 105 packs the decryption key for the content 113 into the license SC and sends it to the requesting end user. The key is encrypted in a way that only authorized users can retrieve it. If the end user's request is not verifiable, incomplete, or not allowed, the clearinghouse 105 rejects the decryption key request.
The clearinghouse 105 keeps a record of all transactions and records them immediately, periodically or in a restricted manner to responsible parties such as Electronic Digital Content Store 103 and Content Provider 101. Can be reported. This report is a means by which content provider 101 is informed about the sale of content 113 and by which electronic digital content store 103 can obtain an audit trail of electronic distribution to its customers. The clearinghouse 105 may also notify the content provider 101 and / or the electronic digital content store 103 if it detects that the information in the SC has been compromised or does not comply with the terms of use of the content. The clearinghouse 105 database transaction recording and repository features are configured for data mining and report generation.
In another embodiment, the clearinghouse 105 can provide customer support and transactional exception handling such as refunds, transmission failures, purchasing disputes, and so on. The clearinghouse 105 operates as an independent entity and can be a trusted administrator of rights management and measurement. Clearinghouse 105 provides billing and clearing as needed. Examples of electronic clearinghouses include Secure-Bank.com and Visa / Mastercard's SET (Secure Electronic Transaction). In one embodiment, the clearinghouse 105 is a website accessible from the end user device 109. In another embodiment, the clearinghouse 105 is part of an electronic digital content store 103.
5. End User Device 109 The end user device 109 can be a player device that includes an end user player application 195 (described later) that complies with the Secure Digital Content Electronic Distribution System 100 specification. These devices include PCs<sub>S</sub>, Set-top box (IRD), and Internet equipment. The end-user player application 195 can be implemented in software and / or consumer electronics hardware. In addition to performing playback, recording, and library management functions, the end-user player application 195 performs SC processing to enable rights management on the end-user device 109. The end-user device 109 manages the download and storage of the SC containing the digital content, requests the clearing house 105 for the encrypted digital content key, manages its receipt, and the digital content is copied or replayed. Processes watermarks each time, manages the number of copies made (or deleted) according to the terms of use of digital content, and performs copies to external media or portable consumer devices where permitted. To do. The portable consumer device can perform a subset of the functionality of the end-user player application 195 to handle the terms of use of the content embedded in the watermark. The terms end-user and end-user player application 195 are used throughout this specification to mean through the use of end-user equipment 109 or execution on end-user equipment 109.
6. Transmission Infrastructure 107 The secure digital content electronic distribution system 100 is independent of the transmission network connecting the electronic digital content store 103 and the end-user device 109. The secure digital content electronic distribution system 100 supports both a two-point model such as the Internet and a broadcast distribution model such as digital broadcast television.
The same tools and applications are used to capture, package, and track transactions for content 113 across different transmission infrastructures 107, but the presentation and the way services are delivered to customers is the infrastructure of choice. May change depending on structure and distribution model. The quality of the transferred content 113 may also change. This is because high-bandwidth infrastructures can deliver high-quality digital content with more acceptable response times than low-bandwidth infrastructures. Service applications designed for the two-point distribution model can be adapted to support the broadcast distribution model as well.
C. Using the System The Secure Digital Content Electronic Distribution System 100 enables secure distribution of high quality electronic copies of Content 113 to end-user devices 109, either consumers or businesses. Allows adjustment and tracking of 113 usage.
The Secure Digital Content Electronic Distribution System 100 can be deployed in a variety of consumer and enterprise-to-enterprise services using both new and existing distribution channels. Each particular service can use different financial models that can be implemented through the rights management features of the Secure Digital Content Electronic Distribution System 100. Models such as wholesale or retail purchases, pay-per-listening fees, purchase contract services, copy-restricted / copy-unlimited, or redistributables through clearinghouse 105 rights management and end-user player application 195 copy protection capabilities. Can be carried out.
The Secure Digital Content Electronic Distribution System 100 gives electronic digital content stores 103 and intermediary market partners a great deal of flexibility in creating services to sell content 113. At the same time, Content Provider 101 is given a level of guarantee that their digital assets will be protected and measured, and as a result, they will be eligible to receive appropriate rewards for licensing Content 113.
II. Cryptographic Concept and Application to Secure Digital Content Electronic Distribution System License control for Secure Digital Content Electronic Distribution System 100 is based on the use of cryptography. This section introduces the basic cryptographic techniques of the present invention. The use of public key cryptography, symmetric key cryptography, digital signatures, digital watermarks, and digital certificates is known.
A. Symmetrical Algorithm In the Secure Digital Content Electronic Distribution System 100, content provider 101 uses a symmetric algorithm to encrypt content. This is called a symmetric algorithm because the same key is used to encrypt and decrypt the data. The data sender and the message receiver must share the key. This shared key is referred to herein as a symmetric key. The architecture of the Secure Digital Content Electronic Distribution System 100 is independent of the particular symmetric algorithm chosen for the particular embodiment.
Common symmetric algorithms are DES, RC2, and RC4. Both DES and RC2 are block ciphers. Block ciphers use a block of data bits at 1 o'clock to encrypt data. DES is a US government-approved encryption standard with a 64-bit block size and a 56-bit key. Triple DES is commonly used to increase the security achieved with simple DES. RSAData Security designed RC2. RC2 uses variable key size cryptography and has a 64-bit block size. RC4, also designed by RSA Data Security, is a variable key size stream cipher. Stream cipher manipulates one data bit at one hour. RSA Data Security claims that RC4 requires 8 to 16 machine operations per byte of output.
IBM has designed a fast algorithm called SEAL. SEAL is a stream algorithm that uses variable length keys and is optimized for 32-bit processors. SEAL requires about 5 basic machine instructions per data byte. A 50MHz 486-based computer runs SEAL code at 7.2MB / s if the 160-bit key used is already preprocessed and stored in an internal table.
In its Overview of CryptoAPI document, Microsoft reported the results of its cryptographic performance benchmarks. These results were obtained by an application using Microsoft's CryptoAPI on a computer running Windows® NT 4.0 on a 120MHz Pentium® basis.
<tables num="1"><img file="JP2005122708A_D0001.tif" /></tables>
B. Public Key Algorithm In the Secure Digital Content Electronic Distribution System 100, symmetric keys and other small data are encrypted using the public key. The public key algorithm uses two keys. The two keys are mathematically related, and as a result, data encrypted with one key can only be decrypted with the other key. The key owner keeps one key (private key) secret and distributes the second key (public key) to the public.
In order to use the public key algorithm to protect the transmission of sensitive messages, the receiving public key must be used to encrypt the message. Only the recipient with the relevant private key can decrypt the message. Public key algorithms are also used to generate digital signatures. A private key is used for that purpose. The next section provides information about digital signatures.
The most commonly used public key algorithm is RSA public key cryptography. RSA has become the de facto public key standard in the industry. Other algorithms that work equally well for encryption and digital signatures are ElGamal and Rabin. RSA is a variable key length cipher.
Symmetric key algorithms are much faster than public key algorithms. In software, DES is generally at least 100 times faster than RSA. For this reason, RSA is not used to encrypt large amounts of data. RSA Data Security is a 90MHz Pentium® computer with RSA Data Security toolkit BSAFE 3.0 using the 512-bit method at 21.6 kbps and the 1024-bit method at 7.4 kbps. Reported to have a throughput of private key operations in seconds (encryption or decryption using the private key).
C. Digital Signature In the Secure Digital Content Electronic Distribution System 100, the issuer of the SC protects the integrity of the SC by digitally signing it. In general, in order to create a digital signature for a message, the message owner first calculates the message digest (as defined below) and then uses the owner's private key to encrypt the message digest. To do. The message will be distributed with its signature. The recipient of the message can verify the digital signature by first decrypting the signature using the message owner's public key and then recovering the message digest. The recipient then calculates a digest of the received message and compares it to the recovered digest. If the message has not been modified during distribution, the calculated digest and the recovered digest must be equal.
In the secure digital content electronic distribution system 100, since the SC contains a plurality of data parts, the digest is calculated for each part, and the total digest is calculated for the concatenated partial digest. The total digest is encrypted using the SC issuer's private key. The encrypted total digest becomes the digital signature of the SC issuer. The partial digest and digital signature are included in the body of the SC. The recipient of the SC can verify the integrity of the SC and its parts by means of the received digital signature and partial digest.
A one-way hash algorithm is used to calculate the message digest. The hash algorithm takes a variable-length input message and converts it into a fixed-length string or message digest. The one-way hash algorithm works in only one direction. That is, it is easy to calculate the digest from the input message, but it is very difficult (calculatively infeasible) to generate the input message from the digest. Due to the nature of the one-way hash function, the message digest can be thought of as the fingerprint of the message.
More common one-way hash functions are the RSA Data Security MD5 and the SHA designed by the NIST (National Institute of Standards and Information Technology).
D. Digital Certificates Digital certificates are used to authenticate or verify the identity of the person or entity that sent the digitally signed message. A certificate is a digital document issued by a certification authority that ties a public key to a person or entity. The certificate contains the public key, the name of the person or entity, the expiration date, the name of the certification authority, and other information. The certificate also includes the digital signature of the certification authority.
When an entity (or person) sends a message signed with its private key and attached with a digital certificate, does the recipient of the message accept the message using the name of the entity in the certificate? Decide whether or not.
In the secure digital content electronic distribution system 100, all SCs except those issued by the end-user device 109 include the certificate of the creator of the SC. The end-user device 109 does not need to include the certificate in its SC, as many end-user devices do not even obtain a certificate or have a certificate issued by a non-authentic certification authority. In the secure digital content electronic distribution system 100, the clearinghouse 105 has the option of issuing a certificate to the electronic digital content store 103. This allows the end-user device 109 to independently verify that the electronic digital content store 103 has been authenticated by the secure digital content electronic distribution system 100.
E.SC Graphical representation guide This document graphically represents the SC using drawings showing encrypted, unencrypted, encryption keys, and certificates. With reference to FIG. 5, FIG. 5 is a diagram of an example of SC200. The following symbols are used in the SC diagram. Key 201 is a public key or a private key. The tooth of the key, eg CLRNGH, which represents a clearinghouse, indicates the owner of the key. The PB in the handle indicates that it is a public key, so key 201 is the clearinghouse public key. The PV in the handle indicates that it is a private key. The diamond is the end-user digital signature 202. The acronym indicates the private key used to create that signature, and therefore the EU is the end user's digital signature from the table below. The symmetric key 203 is used to encrypt the content. The encrypted symmetric key object 204 includes a symmetric key 203 encrypted using CLRNGH's PB. The key on the top of this rectangle is the key used to encrypt the object. The symbol or text inside the rectangle represents an encrypted object (symmetric key in this example). Another encrypted object, transaction ID encrypted object 205, is shown in this example. In addition, there are terms of use 206 for content licensing management described below. The SC200 includes Terms of Use 206, Transaction ID Cryptographic Object 205, Application ID Cryptographic Object 207, and Encrypted Symmetric Key Object 204, all of which are signed by the end-user digital signature 202. ..
The following table shows the acronyms that identify the signers of the SC.<tables num="2"><img file="JP2005122708A_D0002.tif" /></tables>
F. Secure Container Encryption Examples The tables and diagrams below outline the encryption and decryption process used to create and recover information from the SC. The SC created and deciphered in the outline of this process is a general SC. It does not represent the particular SC type used to manage the rights of the Secure Digital Content Electronic Distribution System 100. This process comprises the steps described in FIG. 6 for the encryption process.
Processing Flow of Encryption Process in Figure 6 Process 301 The source generates a random symmetric key and uses it to encrypt the content. 302 The source applies the encrypted content to a hash algorithm to create a content digest. 303 The source uses the receiving public key to encrypt the symmetric key. PB RECPNT refers to the receiving public key. 304 The source applies an encrypted symmetric key to the same hash algorithm used in step 2 to create a symmetric key digest. 305 The source creates an SC digest by concatenating the content digest and the symmetric key digest with the same hash algorithm used in step 2. 306 The source encrypts the SC digest with the source's private key to create the SC's digital signature. PV SENDER refers to the source's private key. 307B The source creates an SC file that contains the encrypted content, the encrypted symmetric key, the content digest, the symmetric key digest, the source certificate, and the SC signature. 307A The sender must have obtained a certificate from a certification authority before initiating secure communication. The certification authority signs the certificate, including the source's public key and the source's name. PV CAUTHR refers to the private key of the certification authority. The sender sends the SC to the receiver.
Processing flow step of decoding processing in Fig. 7 Processing 408 The receiving side receives the SC and separates its parts. 409 The recipient verifies the digital signature of the sender's certificate by decrypting the digital signature of the sender's certificate using the certificate authority's public key. If the digital signature of the certificate is valid, the recipient obtains the sender's public key from the certificate. 410 The recipient uses the source's public key to decrypt the SC digital signature. This restores the SC digest. PB SENDER refers to the source public key. 411 The recipient applies the concatenation of the received content digest and the encrypted key digest to the same hash algorithm that the source used to calculate the SC digest. 412 The recipient compares the calculated SC digest with the SC digest recovered from the source digital signature. If they are the same, the receiving side confirms that the received digest has not been changed and continues the decoding process. If they are not the same, the recipient discards the SC and notifies the sender. 413 The recipient applies the encrypted symmetric key to the same hash algorithm used to calculate the symmetric key digest in step 411. 414 The receiving side compares the calculated symmetric key digest with the symmetric key digest received in the SC. If they are the same, the recipient knows that the encrypted symmetric key has not been modified. The receiving side continues the decoding process. If it is not valid, the recipient discards the SC and notifies the sender. 415 The recipient applies the encrypted content to the same hash algorithm used to calculate the content digest in step 411. 416 The recipient compares the calculated content digest with the content digest received within the SC. If they are the same, the recipient knows that the encrypted content has not been modified. The receiving side continues the decoding process. If it is not valid, the recipient discards the SC and notifies the sender. 417 The receiving side uses the receiving side's private key to decrypt the encrypted symmetric key. This restores the symmetric key. PV RECPNT refers to the receiving private key. 418 The recipient uses a symmetric key to decrypt the encrypted content. This will restore the content.
III. Flow of Secure Digital Content Electronic Distribution System The Secure Digital Content Electronic Distribution System 100 consists of multiple components used by different participants in the system. This participant includes a content provider 101, an electronic digital content store 103, an end user via an end user device 109, and a clearinghouse 105. Use the high-level system flow as an overview of the Secure Digital Content Electronic Distribution System 100. This flow, outlined below, tracks content flowing through System 100. In addition, it outlines the steps participants use to make transactions for purchasing, unlocking, and using Content 113. Some of the assumptions made in this system flow include: -This is the system flow of a digital content service (two-point interface to a PC). Content provider 101 submits audio digital content in PCM uncompressed format (as an example of music audio). Content provider 101 has metadata in an ODBC compliant database, content provider 101 inputs data directly into the content information processing subsystem, or supplies data in a predetermined ASCII file format. -Accounting settlement is carried out by an electronic digital content store. Content 113 is hosted on a single content hosting site 111.
It will be appreciated by those skilled in the art that these assumptions can be modified to accommodate the exact nature of digital content, such as music, video, and program and electronic distribution system broadcasts.
The following processing flow is shown in Figures 1 to 4. Step Process 121 The uncompressed PCM audio file is served as content 113 by content provider 101. The file name is entered into workflow manager 154 with a unique identifier for content 113 in content provider 101. 122 Metadata is collected by the content information processing subsystem in the content provider's database 160 using the unique identifier of content 113 in the content provider 101 and the information provided by the database mapping template. 123 Use workflow manager tool 154 to direct the content flow through acquisition and preparatory processing at content provider 101. Workflow Manager Tool 154 can also be used to track the status of parts of content in the system at any given time. 124 The terms of use for Content 113 are entered into the Content Information Processing subsystem, which can be done either manually or automatically. This data includes copy restriction rules and other business rules that are deemed necessary. All of the metadata input can be done in parallel with the audio processing of the data. 125 Use the water marking tool to hide the data that content provider 101 deems necessary to identify the content within content 113. This can include when it was collected, where it came from (this content provider 101), or other information specified by content provider 101. -Content processing tool 125 performs equalization, dynamic property adjustment, and resampling of content 113 as required for the different supported compression levels. -Compress the content 113 to the desired compression level using the content processing tool 125. The content 113 can then be played back to verify that the compression created the required quality level for the content 113. If desired, equalization, dynamic property adjustment, compression, and reproduction quality inspection can be performed as many times as desired. -Encrypt content 113 and a subset of its metadata by an SC packer using a symmetric key. The tool then uses the clearinghouse 105 public key to encrypt that key to create an encrypted symmetric key. Since the only entity that can decrypt this key is the clearinghouse 105, it can be sent anywhere without jeopardizing the security of content 113. 126 The SC packer tool 152 packs the encrypted symmetric key, metadata, and other information about the content 113 into the metadata SC. 127 Pack the encrypted content 113 and metadata into the content SC. At this point, the processing of content 113 and metadata is complete. 128 Send the metadata SC to content promotion website 156 using a content distribution tool (not shown). 129 The content distribution tool sends the content SC to the content hosting site 111. The content hosting site can reside in a content provider 101, a clearinghouse 105, or a special location dedicated to content hosting. The URL of this site is part of the metadata added to the Metadata SC. 130 Content Promotion Website 156 notifies Electronic Digital Content Store 103 about the new content 113 added to System 100. 131 Using the content acquisition tool, the electronic digital content store 103 downloads the metadata SC corresponding to the content 113 it wants to sell. 132 The electronic digital content store 103 uses a content acquisition tool to extract data from the metadata SC that it wants to use to promote content 113 on its website. Access to parts of this metadata can be protected and charged if desired. 133 Enter the terms of use for content 113, which is unique to the electronic digital content store 103, using the content acquisition tool. These terms of use include retail prices and copy / playback restrictions for different compression levels of Content 113. 134 Electronic Digital Content Store 103's unique terms of use and original metadata SC are packed into the offer SC with the SC packer tool. 135 After updating the website of Electronic Digital Content Store 103, Content 113 will be available to end users visiting the Web. 136 When the end user finds the content 113 he wants to purchase, he clicks on a content icon, such as a music icon, and the item is added to the end user's shopping cart maintained by the electronic digital content store 103. When the end user completes the shopping, he submits a purchase request to the electronic digital content store 103 for processing. 137 Electronic Digital Content Store 103 interacts with the credit card clearing organization to secure funding in the same way it currently operates. 138 After receiving the credit card authentication number from the credit card clearing organization, the electronic digital content store 103 stores the credit card authentication number in the database and calls the SC packer tool to create the transaction SC. This transaction SC includes all of the offer SCs for the content 113 purchased by the end user, the transaction ID that can be traced back to the electronic digital content store 103, the information that identifies the end user, the compression level of the purchased song, and so on. Includes terms of use and price list. 139 This transaction SC is sent to the end user device 109. 140 When the transaction SC reaches the end user device 109, the end user player application 195 is started, opens the transaction SC, and confirms the end user's purchase. The end-user player application 195 can open individual offer SCs and, in an alternative embodiment, inform the user of an estimated download time. The end-user player application 195 then asks the user to specify when to download the content 113. 141 The end-user player application 195 awakens based on the time the end-user requests the download, and in particular creates an order SC containing the encrypted symmetric key of content 113, the transaction ID, and the end-user information. Starts the download process. 142 Send this order SC to the clearinghouse 105 for processing. 143 The clearinghouse 105 receives the order SC, opens it, and verifies that all of the data has not changed. The clearinghouse 105 verifies the terms of use purchased by the end user. This Terms of Use must comply with the Terms of Use specified by Content Provider 101. This information is logged in the database. 144 After all inspections are completed, the clearinghouse 105 private key is used to decrypt the encrypted symmetric key. The symmetric key is then encrypted using the end user's public key. This newly encrypted symmetric key is packaged in the licensed SC by the SC packer. 145 Send the license SC to the end user. 146 When the end-user device 109 receives the license SC, the license SC is stored in memory until the content SC is downloaded. 147 The end-user device 109 sends the corresponding license SC to the content hosting facility 111 to request the purchased content 113. 148 Content 113 is transmitted to the end user device 109. Upon reception, the content 113 is decrypted by the end-user device 109 using a symmetric key.
IV. Rights Management Architecture Model A. Functions of Architecture Layer Figure 8 is a block diagram of the rights management architecture of the secure digital content electronic distribution system 100. Architecturally, the four layers, namely the license control layer 501, the content identification layer 503, the content usage control layer 505, and the content formatting layer 507, represent the secure digital content electronic distribution system 100. The overall functional objectives of each layer and the individual key functions of each layer are described in this section. The function of each layer is fairly independent of the function of the other layers. Within a broad limitation, the function of one layer can be replaced with a similar function without affecting the function of another layer. Obviously, the output of one layer needs to satisfy the format and semantics that the adjacent layer can accept.
License control layer 501 guarantees: -Digital content is protected from unauthorized interception and modification during distribution. Content 113 originates from a legitimate content owner and is distributed by a licensed distributor, such as an electronic digital content store 103. The digital content purchaser has a properly licensed application. The Distributor receives payment from the Buyer before a copy of Content 113 is made available to the Buyer or End User. -Transaction records are kept for reporting.
The content identification layer 503 enables verification of copyright and identification of content purchasers. Content copyright information and content purchaser identification allow tracking of the source of authorized or unauthorized copies of Content 113. Therefore, the content identification layer 503 provides a means of combating piracy.
Content usage control layer 505 ensures that a copy of content 113 is used on the purchaser's device in accordance with store usage conditions 519. The store usage condition 519 allows you to specify the number of views and local copies allowed for Content 113 and whether Content 113 can be recorded on an external portable device. The functions of the content usage control layer 505 track the copy / playback usage of the content and update the copy / playback status.
The content formatting layer 507 converts the format of the content 113 from the native representation of the content 113 at the content owner's facility to a format consistent with the service functions and distribution means of the secure digital content electronic distribution system 100. To enable. The conversion process can include compression coding and related preprocessing, such as frequency equalization and amplitude dynamic adjustment. In the case of audio content 113, the purchaser also needs to process the received content 113 to achieve a format suitable for playback or transfer to a portable device.
B. Functional Classification and Flow The rights management architecture model is shown in Figure 8, which maps the architecture layers to the operating components that make up the Secure Digital Content Electronic Distribution System 100 and the key to each layer. It is a figure which shows the function.
1. Content Formatting Layer 507 Common features related to Content Formatting Layer 507 are content preprocessing 502 and content compression 511 of content provider 101 and content descramble 513 and content decompression of end-user device 109. It is 515. Examples of pretreatment requirements and specific functions are described above. Content compression 511 is used to reduce the file size and transmission time of content 113. Any compression algorithm suitable for the content 113 and the type of transmission medium can be used in the secure digital content electronic distribution system 100. For music, MPEG 1/2/4, Dolby AC-2 and AC-3, Sony Adaptive Transform Coding (ATRAC), and low bit rate algorithms, are some of the compression algorithms typically used. Content 113 is stored in end-user equipment 109 in compressed form to reduce storage size requirements. Content 113 is decompressed during active playback. Descramble is also performed during active playback. The purpose and type of scrambling will be described later in the description of the content usage control layer 505.
2. Content Usage Control Layer 505 The Content Usage Control Layer 505 enables the specification and enforcement of conditions or constraints imposed on the use of content 113 by the end-user device 109. The conditions specify the allowed number of views of content 113, whether secondary copy of content 113 is allowed, the number of secondary copies, and whether content 113 can be copied to an external portable device. be able to. Content provider 101 sets acceptable terms of use 517 and sends them within the SC to electronic and digital content store 103 (see section 501 for license control layer 501). Electronic Digital Content Store 103 may add or narrow Terms of Use 517 as long as it does not violate the original terms set by Content Provider 101. The electronic digital content store 103 transmits all store terms of use 519 (within the SC) to the end-user device 109 and the clearinghouse 105. The clearinghouse 105 performs condition-of-use validation 521 before allowing the content 113 to be published to the end-user device 109.
The implementation of the content usage condition 517 is executed by the content usage control layer 505 of the end user apparatus 109. First, upon receipt of the content 113, the copy from the content identification layer 503 of the end-user device 109 marks the content 113 with a copy / playback code 523 representing the first copy / playback permission. Second, the player application 195 cryptographically scrambles the content 113 before storing it in the end-user device 109. The player application 195 generates a scrambled key for each content item, which is encrypted and hidden in the end-user device 109. Then, each time the end-user device 109 accesses the content 113 for copying or playback, the end-user device 109 validates the copy / playback code before allowing the content 113 to be descrambled and played or copied. To do. The end-user device 109 appropriately updates all copy / playback codes of the original copy of the content 113 and the new secondary copy. Copy / playback coding is performed on the compressed content 113. That is, it is not necessary to decompress the content 113 before embedding the copy / playback code.
The end-user device 109 uses the license watermark 527 to embed the copy / playback code in the content 113. Only the end-user player application 195, who knows the embedding algorithm and the associated scrambling key, can read or modify the embedded data. This data cannot be seen or heard by a human observer, i.e., this data does not introduce perceptible degradation into content 113. Watermarks withstand the signal degradation introduced by multiple steps of content processing, data compression, digital-to-analog conversion, analog-to-digital conversion, and normal content processing, so watermarks are in all forms of representation, including analog representations. Accompanied by the content 113 of. In an alternative embodiment, instead of embedding the copy / playback code in content 113 using license watermark 527, end-user player application 195 uses terms of use 519 stored in a protected manner.
3. Content Identification Layer 503 As part of Content Identification Layer 503, Content Provider 101 also uses License Watermark 527 to include content identifiers, content owners, and other information such as publication dates and geographic distribution zones. Data is embedded in the content 113. This watermark is called the copyright watermark 529. Upon receipt, the end-user device 109 uses the content purchaser's name and transaction ID 535 (see Section 501 of License Control Layer 501 below) and other information such as the license date and terms of use 517 for content 113. Watermark the copy. This watermark is referred to herein as a licensed watermark. A copy of Content 113, whether obtained in an authorized or unauthorized form, is subject to audio processing that preserves content quality and carries copyright and license watermarks. The content identification layer 503 deters piracy.
4. License Control Layer 501 License Control Layer 501 protects Content 113 from unauthorized interception, has a properly licensed end-user device 109, and has a license purchase transaction with an authorized Electronic Digital Content Store 103. Guarantee that content is published only on an individual basis to end users who have successfully completed. License control layer 501 protects content 113 with double encryption 531. Content 113 is encrypted using the cryptographic symmetric key generated by content provider 101, which is encrypted using the clearinghouse public key 621. Initially, only the clearinghouse 105 can recover the symmetric key.
The license control is designed using the clearinghouse 105 as a "trusted party". Prior to publishing the grant for license request 537 (ie, symmetric key 623 for content 113 to end-user equipment 109), clearing house 105 must have transaction 541 and license grant 543 complete and authentic. And verify that the electronic digital content store 103 has permission from the secure digital content electronic distribution system 100 for the sale of the electronic content 113 and that the end user has a properly licensed application. .. Audit / Report 545 enables report generation and sharing of licensing transaction information with other authorized parties within the Secure Digital Content Electronic Distribution System 100.
License control is implemented via SC process 533. The SC is used to distribute encrypted content 113 and information among system operations components (see the SC Detailed Structure section below). SCs are cryptographic carriers of information that use cryptographic encryption, digital signatures, and digital certificates to provide protection against unauthorized interception and modification of electronic information or content 113. SC also enables authenticity verification of electronic data.
License control requires Content Provider 101, Electronic Digital Content Store 103, and Clearinghouse 105 to have a genuine cryptographic digital certificate from a trusted certification authority used to certify these components. To do. The end-user device 109 does not need to have a digital certificate.
C. Content distribution and license issuance control FIG. 9 is a block diagram showing an outline of content distribution and license issuance control applied to the license control layer of FIG. In this figure, an electronic digital content store 103, an end-user device 109, and a clearinghouse 105 are interconnected over the Internet, and unicast (two-point) transmission is used between these components. The case is shown. Communication between the content provider 101 and the electronic digital content store 103 may also be via the Internet or other networks. It is assumed that the content purchase commerce transaction between the end user device 109 and the electronic digital content store 103 is based on the standard Internet web protocol. As part of the web-based dialogue, the end user makes a selection of content 113 to purchase, provides personal and accounting information, and agrees to the terms of the purchase. The electronic digital content store 103 can obtain payment permission from the acquiring institution using a protocol such as SET.
In FIG. 9, it is also assumed that the electronic digital content store 103 has downloaded the end user player application 195 to the end user device 109 based on the standard web protocol. In this architecture, the electronic digital content store 103 assigns a unique application ID to the downloaded player application 195, which the end-user device 109 stores for later application license verification (see below). Need to do.
The overall licensing flow begins with Content Provider 101. Content provider 101 uses a locally generated cryptographic symmetric key to encrypt content 113 and clearinghouse 105 public key 621 to encrypt symmetric key 623. In an alternative embodiment, the symmetric key can be sent from the clearinghouse 105 to the content provider 101 instead of being generated locally. Content provider 101 creates content SC630 that encloses encrypted content 113 and metadata SC620 that encloses encrypted symmetric key 623, store terms of use 519, and other content 113 related information. For all content 113 objects, there is one metadata SC620 and one content SC630. The content 113 object can be the compression level of one and the same song, each song in the album, or the entire album. For each content 113 object, the metadata SC620 also carries the store usage condition 519 associated with the content usage control layer 505.
Content provider 101 distributes metadata SC620 to one or more electronic digital content stores 103 (step 601) and distributes content SC630 to one or more content hosting sites (step 602). Each electronic digital content store 103 creates an offer SC641. Offer SC641 typically carries much the same information as metadata SC620, including the digital signature 624 of content provider 101 and a digital certificate (not shown for content provider 101). As mentioned above, the electronic digital content store 103 can add or narrow the store usage condition 519 (processed by the content usage control layer) initially defined by the content provider 101. Optionally, content SC630 and / or metadata SC620 can be signed with the digital signature 624 of content provider 101.
After completing the content purchase transaction (step 603) of the end-user device 109 and the electronic digital content store 103, the electronic digital content store 103 creates transaction SC640 and transfers it to the end-user device 109 (step 604). Transaction SC640 includes a unique transaction ID 535, the name of the purchaser (ie, the name of the end user) (not shown), the public key 661 of the end user device 109, and the offer SC641 associated with the purchased content 113. .. Transaction data 642 in FIG. 9 represents both transaction ID 535 and the end user name (not shown). Transaction data 642 is encrypted using the clearinghouse 105 public key 621. Optionally, transaction SC640 is signed with the digital signature 643 of Electronic Digital Content Store 103.
Upon receipt of transaction SC640 (and the offer SC641 contained therein), the end-user player application 195 running on end-user equipment 109 requests the clearinghouse 105 to send a license authorization by order SC650 (step 605). .. Order SC650 contains encrypted symmetric key 623 from offer SC641 and store terms of use 519, encrypted transaction data 642 from transaction SC640, and encrypted application ID 551 from end-user device 109. Is done. In another embodiment, the order SC650 is signed with the digital signature 652 of the end user device 109.
Upon receipt of the order SC650 from the end-user device 109, the clearinghouse 105 verifies the following: 1. Electronic Digital Content Store 103 has permission from Secure Digital Content Electronic Distribution System 100 (exists in database 160 of Clearinghouse 105) 2. Order SC650 has not been modified. Transaction data 642 and symmetric key 623 are complete and authentic 4. Electronic store terms of use 519 purchased by end-user device 109 are consistent with terms of use 517 set by content provider 101. Have 5. Application ID 551 has a valid structure and is supplied by an authorized Electronic Digital Content Store 103.
If the validation is successful, the clearinghouse 105 decrypts the symmetric key 623 and transaction data 642, creates license SC660, and forwards it to end-user equipment 109 (step 606). License SC660 carries symmetric key 623 and transaction data 642, both of which are encrypted using public key 661 of end-user equipment 109. If the verification is unsuccessful, the clearinghouse 105 denies the license to the end-user device 109 and informs the end-user device 109. The clearinghouse 105 immediately informs the electronic digital content store 103 of this verification failure. In an alternative embodiment, the clearinghouse 105 signs license SC660 with its digital signature 663.
After receiving license SC660, the end-user device 109 decrypts the symmetric key 623 and transaction data 642 previously received from the clearinghouse 105 and requests content SC630 from content hosting site 111 (step 607). .. Upon arrival of content SC630 (step 608), the end-user device 109 decrypts content 113 using symmetric key 623 (step 609) and licenses, copies / copies content 113 and transaction data 642. Pass it to layers for replay coding, scrambling, and other processing of content 113 described earlier with respect to FIG.
Finally, the clearinghouse 105 periodically sends a summary transaction report to content provider 101 and electronic digital content store 103 for auditing and tracking (step 610).
V. Structure of the secure container A. General structure The secure container (SC) together defines a unit of content 113 or a part of a transaction, and related information such as terms of use, metadata, and encryption method. It is a structure consisting of multiple parts, which also defines. SCs are designed to verify the integrity, integrity, and authenticity of information. Some of the information in the SC can be encrypted so that it can only be accessed after the correct permissions have been obtained.
The SC contains at least one bill of materials (BOM) portion that has a record of information about the SC and information about each of the parts contained within the SC. The message digest is calculated for each part using a hash algorithm such as MD-5 and is included in the BOM record for that part. The digests of the parts are concatenated with each other, then another digest is calculated and encrypted using the private key of the entity that creates the SC to create a digital signature. The party receiving the SC can use this digital signature to verify the entire digest and, therefore, the integrity and integrity of the SC and all parts thereof.
The following information can be included as a record in the BOM along with the records for each part. The type of SC determines which records should be included. -SC version-SC ID-SC type (eg offer, order, transaction, content, metadata or promotion, and license) -SC issuer-SC creation date-SC expiration date-Clearing house URL-included Description of the digest algorithm used for the part (default is MD-5) -Description of the algorithm used for digital signature encryption (default is RSA) -Digital signature (all ciphers of the concatenated digest of the included part) Digest)
The SC can contain multiple BOMs. For example, the offer SC641 consists of an SC620 portion of the original metadata containing its BOM, as well as additional information and a new BOM added by the Electronic Digital Content Store 103. The BOM record for metadata SC620 is included in the BOM for offer SC641. This record contains a digest of the metadata SC620 BOM that can be used to verify its integrity, and therefore the integrity of the portion contained from the metadata SC620 is also stored in the metadata SC620 BOM. It can be verified using the subdigested value. All of the parts from the metadata SC620 do not have a record in the new BOM created for offer SC641. Only the portion added by the BOM of the electronic digital content store 103 and the metadata SC620 has a record in the new BOM.
The SC can also include the key description part. The key description portion contains a record containing the following information about the encrypted portion in the SC. -The name of the encrypted part. -The name used for that part when it is decrypted. -The encryption algorithm used to encrypt that part. -A key identifier that indicates the public encryption key used to encrypt that part, or an encrypted symmetric key that is used to decrypt the encrypted part when it is decrypted. -The encryption algorithm used to encrypt the symmetric key. This field exists only when the record of the key description part contains the encrypted symmetric key used to encrypt the encrypted part. -The key identifier of the public encryption key used to encrypt the symmetric key. This field exists only when the record of the key description part contains the encrypted symmetric key and the encryption algorithm identifier of the symmetric key used to encrypt the encrypted part.
If the SC does not contain the encrypted part, there is no key description part.
B. Rights Management Language Syntax and Semantics The rights management language consists of parameters that allow the end user to assign values that define restrictions on the use of Content 113 after purchasing Content 113. The restriction on the use of Content 113 is Terms of Use 517. Each content provider 101 specifies a usage condition 517 for each of its 113 content items. Electronic Digital Content Store 103 interprets Terms of Use 517 in Metadata SC620 and uses that information to provide customers with the options they want to offer and to add retail purchase information for Content 113. After the end user has selected the content 113 item for purchase, the end user device 109 requests permission for the content 113 based on the store terms of use 519. The clearinghouse 105 ensures that the requested store terms of use 519 match the acceptable terms of use 517 specified in the metadata SC620 by content provider 101 before sending license SC660 to the end user. Verify.
When the end-user device 109 receives the purchased content 113, the store usage condition 519 is encoded in the content 113 using a water marking tool or stored in a protected form. Encoded within 519. The end-user player application 195 running on the end-user device 109 ensures that the store terms of use 519 encoded in the content 113 are enforced.
The following is an example of the store usage condition 519 of the embodiment when the content 113 is music. Songs can be recorded. The song can be played n times.
C. Secure Container Flow and Processing Overview Metadata SC620 is created by Content Provider 101 and is used to define 113 content items such as songs. Content 113 itself is not included in these SCs. This is because the size of the content 113 is usually too large for the electronic digital content store 103 and the end user to efficiently download the container solely for the purpose of accessing descriptive metadata. .. Instead, this SC contains an external URL (Uniform Resource Locator) that points to content 113. The SC also includes metadata that provides descriptive information and other relevant data about the content 113, such as music, CD cover art, or digital audio clips in the case of the content 113 of the song.
Electronic Digital Content Store 103 downloads the permitted metadata SC620 and creates offer SC641. In short, the offer SC641 consists of parts from the metadata SC620 and some of the BOMs and additional information contained by the Electronic Digital Content Store 103. A new BOM for offer SC641 is created when you create offer SC641. The electronic digital content store 103 also extracts metadata information from the metadata SC620 on a website that represents a description of the content 113 to the end user so that the end user can usually purchase the content 113. Use metadata SC620 by creating an HTML page.
The information in the offer SC641 added by the Electronic Digital Content Store 103 is typically to narrow the selection of Terms of Use 517 specified in the metadata SC620, as well as a graphic image file of the store's logo and a graphic image file of that store's logo. Promotional data such as the URL to the store's website. Metadata The offer SC641 template in SC620 contains information that the electronic digital content store 103 can modify in offer SC641 and any additional information that the electronic digital content store 103 needs, and the metadata that is embedded. Indicates the part held in SC620.
Offer SC641 is included in transaction SC640 when the end user decides to purchase Content 113 from Electronic Digital Content Store 103. The electronic digital content store 103 creates a transaction SC640 and sends it to the end-user device 109, including the offer SC641 for each 113 items of content purchased. The end-user device 109 receives transaction SC640 and verifies the integrity of transaction SC640 and the included offer SC641.
The order SC650 is created by the end user device 109 for each 113 items of content purchased. Contains information from offer SC641, information from transaction SC640, and information from the end-user device 109 configuration file. Orders SC650 are sent to the clearinghouse 105 one at a time. The URL of the clearinghouse 105 to which the order SC650 is sent is included as one of the records in the BOM of the metadata SC620 and is also included in the offer SC641.
The clearinghouse 105 validates and processes the order SC650 and supplies the end-user device 109 with everything needed to access the license watermark 527 and the purchased content 113. One of the functions of the clearinghouse 105 is the decoding of the symmetric key 623, which is required to decrypt the water marking instruction from the offer SC641 and the content 113 from the content SC630. The record of the encrypted symmetric key 623 actually contains more than the actual encrypted symmetric key 623. Prior to performing the encryption, content provider 101 may optionally append its name to the actual symmetric key 623. Encrypting the name of content provider 101 with symmetric key 623 provides security against pirate content provider 101 that creates its own metadata SC620 and content SC630 from legitimate SCs. The clearinghouse 105 verifies that the name of the content provider 101 encrypted with the symmetric key 623 matches the name of the content provider 101 in the SC certificate.
If there are changes that need to be made to the clearinghouse 105 water marking instructions, the clearinghouse 105 decrypts the symmetric key 623, modifies the water marking instructions, and uses the new symmetric key 623. Encrypt the water marking instruction again. This symmetric key 623 is re-encrypted using the public key 661 of the end-user device 109. The clearinghouse 105 also decrypts the other symmetric key 623 of the SC and re-encrypts it with the public key 661 of the end-user device 109. In response to the order SC650, the clearinghouse 105 creates a license SC660 containing a newly encrypted symmetric key 623 and an updated water marking instruction and sends it to the end-user device 109. If the processing of the order SC650 is not completely successful, the clearinghouse 105 returns an HTML page or equivalent to the end-user device 109 informing about the failure of the authorization process.
License SC660 provides end-user equipment 109 with everything needed to access 113 content items. The end-user device 109 requests the content hosting site 111 for the appropriate content SC630. Content SC630 is created by content provider 101, which includes 113 parts of encrypted content and a metadata part. End-user player application 195 uses symmetric key 623 from license SC660 to decrypt content 113, metadata, and water marking instructions. The water marking instruction is then attached to the content 113, which is scrambled and stored in the end user device 109.
D. Formatting the Metadata Secure Container 620 The table below shows the parts contained in the Metadata SC620. Each of the boxes in the "Parts" column is a separate object contained in the SC with the BOM (except for the part names enclosed in [] characters). The BOM contains one record for each part contained in the SC. The Existence of Part column indicates whether the part itself is actually included in the SC, and the Digest column indicates whether a message digest is calculated for that part. Some parts may not be propagated when the SC is included in other SCs (determined by the associated template), but the entire original BOM is propagated. This is because the clearinghouse 105 requires the entire BOM to verify the digital signature contained in the original SC.
In the "Key description part" column of the table below, the records included in the key description part of SC are defined. The key description part record defines information about the encryption key and encryption algorithm used to encrypt the part within the SC or another part within the SC. Each record contains the name of the encrypted part and, if necessary, a URL pointing to another SC contained in the encrypted part. The Result Name column defines the name assigned to that part after decryption. The "Cryptography Algorithm" column defines the encryption algorithm used to encrypt that part. In the "Key ID / Encryption Key" column, either identify the encryption key used to encrypt that part, or base64-encode the bit string of the encrypted symmetric key 623 used to encrypt that part. Either is defined. The "Symmetric Key Algorithm" column is an optional parameter that defines the encryption algorithm used to encrypt the symmetric key 623 when the previous column is the encrypted symmetric key 623. The "symmetric key ID" column is an identification of the encryption key used to encrypt the symmetric key 623 when the "key ID / encryption key" column is the encrypted symmetric key 623.
<tables num="3"><img file="JP2005122708A_D0003.tif" /></tables>
Below, we explain the terms used in the metadata SC table above. -[Content URL] Parameter in the record of the key description part. This is the URL pointing to the encrypted content 113 in the content SC630 associated with this metadata SC620. The metadata SC620 itself does not contain encrypted content 113. -[Metadata URL] Parameter in the record of the key description part. This is the URL that points to the encrypted metadata in the content SC630 associated with this metadata SC620. Metadata SC620 itself does not contain encrypted metadata. -Content ID The part that defines the unique ID assigned to the content 113 item. When the metadata SC620 refers to multiple content 113 items, this part contains multiple content IDs. Metadata In the case of a song, the part that contains information related to 113 items of content such as the artist name and CD cover art. There may be multiple metadata parts, some of which may be encrypted. The internal structure of the metadata part depends on the type of metadata it contains. · Terms of Use A portion that contains information that describes the options, rules, and constraints of use imposed on the end user regarding the use of Content 113. -SC template The part that defines the template that describes the information required to create the offer SC, order SC, and license SC660 and optional information. Water marking order A portion of content 113 that contains encrypted instructions and parameters for performing water marking. Water marking instructions may be modified by the clearinghouse 105 and returned to end-user equipment 109 within license SC660. In the key description part, the encryption algorithm used to encrypt the water marking instruction, the name of the output part used when the water marking instruction is decrypted, and the encryption used to encrypt the water marking instruction. There is a record that defines the base64 encoding of the bit string of symmetric key 623, the encryption algorithm used to encrypt symmetric key 623, and the identification of the public key required to decrypt symmetric key 623. Clearinghouse Certificate A certificate from a certification authority or clearinghouse 105, including the signed public key 621 of the clearinghouse 105. There may be multiple certificates, in which case a hierarchical level structure is used, the highest level certificate contains the public key to open the next level certificate, and the lowest level certificate. Upon reaching the book, the clearinghouse 105 public key 621 is included. Certificate A certificate from a certification authority or clearinghouse 105, including the signed public key 621 of the entity that created the SC. There may be multiple certificates, in which case a hierarchical level structure is used, the highest level certificate contains the public key to open the next level certificate, and the lowest level certificate. Upon reaching the book, the SC author's public key is included. -SC version The version number assigned to the SC by the SC packer tool. -SC ID A unique ID assigned to the SC by the entity that created the SC. -SC type Indicates the type of SC (eg metadata, offers, orders, etc.). -SC issuer Indicates the entity that created the SC. -Creation date The date when the SC was created. -Expiration date The date when the SC expires and is no longer valid. Clearinghouse URL The address of the clearinghouse 105 that the end-user player application 195 must interact with to obtain the correct permission to access content 113. Digest algorithm ID The identifier of the algorithm used to calculate the digest of the parts. Digital Signature Algorithm ID The identifier of the algorithm used to encrypt the digest of the concatenated partial digests. This encrypted value is the digital signature. -Digital signature A digest of a concatenated partial digest encrypted using the public key of the entity that created the SC. -Output part The name assigned to the output part when the encrypted part is decrypted. · The default encryption algorithm used to encrypt RSA and RC4 symmetric keys 623 and data parts. -Cryptographic symmetric key Base64 encoding of the bit string of the encrypted key used to decrypt the SC part when decrypted. -CH public key An identifier indicating that the public key 621 of the clearinghouse 105 was used for data encryption.
E. Format for Offer Secure Container 641 The table below shows the parts contained in Offer SC641. The part except for a part of the metadata part and the BOM from the metadata SC620 are also included in the offer SC641.
<tables num="4"><img file="JP2005122708A_D0004.tif" /></tables>
Below, I will explain the terms used in the offer SC641 above that were not previously explained for another SC. -Metadata SC BOM BOM from the original metadata SC620. The BOM record for offer SC641 contains a digest of the BOM for metadata SC620. Additional / Modified Fields Terms of Use information modified by Electronic Digital Content Store 103. This information is verified by the clearinghouse 105 by the received SC template to ensure that all changes made by the electronic digital content store 103 are within the scope of its permission. Electronic Digital Content Store Certificate A certificate supplied by Clearinghouse 105 to Electronic Digital Content Store 103 and signed by Clearinghouse 105 using the Clearinghouse 105's private key. This certificate is used by the end-user player application 195 to verify that the electronic digital content store 103 is a valid distributor of content 113. The end-user player application 195 and the clearinghouse 105 identify that the electronic digital content store 103 is an authorized distributor by decrypting the certificate with the clearinghouse 105's public key 621. Can be verified. The end-user player application 195 stores a local copy of the clearinghouse 105 public key 621 received as part of the initial setup during installation.
F. Format of Transaction Secure Container 640 The table below shows the transaction SC640 and its BOM and key description parts.
<tables num="5"><img file="JP2005122708A_D0005.tif" /></tables>
Below, I will explain the terms used in transaction SC640 above that were not previously explained for another SC. Transaction ID 535 An ID assigned by the Electronic Digital Content Store 103 to uniquely identify the transaction. -End User ID The identification of the end user obtained by the electronic digital content store 103 when the end user makes a purchase selection and provides credit card information. End-user public key The end-user public key 661 used by the clearinghouse 105 to re-encrypt the symmetric key 623. The end user's public key 661 is transmitted to the electronic digital content store 103 during the purchase transaction. · Offer SC Offer SC641 for 113 items of purchased content. · Content usage selection An array of terms of use for each 113 content items purchased by the end user. There is one item for each offer SC641. -HTML to be displayed One or more HTML pages displayed by the end user player application 195 in an internet browser window when receiving transaction SC640 or during a dialogue between end user equipment 109 and clearinghouse 105.
When the end-user device 109 receives transaction SC640, the following steps can be taken to verify the integrity and authenticity of the SC. 1. Verify the integrity of the certificate of the electronic digital content store 103 using the public key 621 of the clearinghouse 105. The public key 621 of the clearinghouse 105 is stored in the end user device 109 after being received as part of the initial configuration of the end user player application 195 during the installation of the end user player application 195. 2. Validate the SC's digital signature 643 using the public key from the Electronic Digital Content Store 103 certificate. 3. Verify the hashes of the parts of the SC. 4. Verify the integrity and authenticity of each offer SC641 contained in transaction SC640.
G. Format of Order Secure Container 650 The following table shows the Order SC650 and its BOM and key description parts. These parts either provide information to the clearinghouse 105 for decryption and verification purposes, or are verified by the clearinghouse 105. The portion from offer SC641 and the BOM are also included in order SC650. The "part" in the "Part Existence" column of the BOM of the metadata SC indicates that some of these parts are not included in the order SC650. The BOM from the metadata SC620 is also included unchanged, allowing the clearinghouse 105 to verify the integrity of the metadata SC620 and its parts.
<tables num="6"><img file="JP2005122708A_D0006.tif" /></tables><tables num="7"><img file="JP2005122708A_D0007.tif" /></tables>
Below, I will explain the terms used in the order SC650 above that were not previously explained for another SC. -Transaction SC BOM The BOM of the original transaction SC640. The records in the BOM of the order SC650 contain a digest of the BOM of the transaction SC640. · Encrypted credit card information Optional encrypted information from the end user used to charge a credit or debit card for a purchase. This information is needed when the electronic digital content store 103 that created the offer SC641 does not process the bill to the customer (in which case the clearinghouse 105 can process the bill).
H. Format of License Secure Container 660 The table below shows the parts contained in License SC660 and its BOM. As shown in the key description section, the symmetric key 623 required to decrypt the watermarking instructions, content 113, and content 113 metadata is re-used by the clearinghouse 105 using the end user's public key 661. It is encrypted. Upon receipt of license SC660, the end-user device 109 decrypts the symmetric key 623 and uses them to access the encrypted portion from license SC660 and content SC630.
<tables num="8"><img file="JP2005122708A_D0008.tif" /></tables>
Below, I will explain the terms used in the license SC660 above that were not previously explained for another SC. EU public key An identifier that indicates that the end user's public key 661 was used to encrypt the data. -Order SC650 id The SC ID taken from the BOM of the order SC650. -Certificate Revocation List An optional list of certificate IDs that were previously issued, signed by the Clearinghouse 105, but are no longer considered valid. All SCs with signatures that can be verified by the certificate included in the revocation list are invalid SCs. The end-user player application 195 stores a copy of the clearinghouse 105 certificate revocation list in the end-user device 109. Whenever a revocation list is received, the end-user player application 195 replaces it with a local copy if the revocation list is newer. The revocation list contains a version number and / or time stamp to determine which list is the newest.
I. Content Secure Container Format The table below shows the parts included in the Content SC630 and BOM.
<tables num="9"><img file="JP2005122708A_D0009.tif" /></tables>
Below are some terms used in the content SC630 above that were not previously explained for another SC. · Encrypted content Content 113 encrypted by content provider 101 using symmetric key 623. · Encrypted metadata Metadata associated with content 113, encrypted by content provider 101 using symmetric key 623.
Since the key required to decrypt the encrypted part is in the license SC660 created by the clearinghouse 105, the content SC630 does not include the key description part.
VI. Secure Container Packing and Unpacking A. Overview The SC packer is a 32-bit Windows (registered) with an API (Application Programming Interface) that can be called in either a multi-step or single-step process to create an SC using all of the specified parts. It is a trademark) program. SC Packer Tools 151, 152, and 153 support various Windows® programs for Content Provider 101, Clearinghouse 105, Electronic Digital Content Store 103, and other sites that require SC packing. Runs on various hardware platforms. A BOM and, if necessary, a key description part are created and included in the SC. A set of packer APIs can be used by the caller to generate a record of the BOM and key description part and specify the information needed to include the parts in the SC. The encryption of the parts and symmetric key 623 and the calculation of the digest and digital signature are also performed by the packer. Cryptographic and digest algorithms supported by the packer are either included in the packer code or called through an external interface.
The interface to the packer for creating an SC is provided by an API that accepts the following parameters as input. -A pointer to the buffer of the concatenated structure. Each structure in the buffer is a command to the packer that contains the information needed to execute the command. Packer commands include adding the part with the associated BOM record to the SC, adding the record to the BOM, and adding the record to the key description part. -A value that indicates the number of concatenated structures contained in the buffer described above. -The name and position of the BOM part. A value in which each bit is a defined flag or a reserved flag for future use. Currently, the following flags are defined. -Indication of whether to bundle all parts of the SC together into a single file after processing all the structures in the buffer. Bundled parts into a single object is the last step performed when creating an SC. -Indication about whether to omit the digital signature from the BOM part. If this flag is not set, the digital signature is calculated just before bundling the SC into a single object.
In an alternative embodiment, the interface to the packer for creating the SC is provided by an API that accepts the following parameters as input. -First, call the API, the information used to initialize the SC settings, the name used for the BOM part, the default position to look for the added part, and the flag value, which are represented as IP records in the SC BOM part. Create a bill of materials (BOM) part by passing a pointer to a structure consisting of. This API returns the SC handle used by subsequent packer APIs. -Packers have an API that is always used when adding parts to the SC. This API accepts the SC handle returned by the previous packer API, a pointer to a structure consisting of information about the parts to be added, and flag values. Information about the part to be added includes the name and location of the part, the name used in the BOM for that part, the type of part to be added, the hash value of that part, the flags, and so on. -After adding all the parts to the SC, call the packer API to pack all the parts, including the BOM part, into a single SC object, which is usually a file. This API accepts the SC handle returned by the previous packer API, the name used for the packed SC, a pointer to a structure containing information for signing the SC, and flag values.
Either the packer or the entity that calls the packer can use the SC template to create an SC. The SC template has the information that defines the necessary parts and records in the created SC. The template can also define the encryption method and encryption key reference used to encrypt the symmetric key 623 and the part to be encrypted.
The packer has an API used to unpack the SC. Unpacking the SC is the process of taking the SC and separating it into individual parts. You can then call the packer to decrypt any of the encrypted parts unpacked from the SC.
B. Bill of Materials (BOM) Part The BOM part is created by the packer as the SC is being created. A BOM is a text file that contains a record of information about the SC and about the parts contained in the SC. Each record in the BOM is on a single line, with a line break indicating the beginning of a new record. The BOM typically contains a digest of each part and a digital signature that can be used to verify the authenticity and integrity of the SC. The record types in the BOM are:
IP The IP record contains a pair of "name = value" pairs associated with the SC. The following names are reserved for certain characteristics of SC. V major.minor.fix The V characteristic specifies the SC version. This is the version number of the SC specification that SC created under it. The string following the V must be in the form major.minor.fix, where major, minor, and fix are the major release number, minor release number, and fix level, respectively. ID value The ID characteristic is a unique value assigned to this particular SC by the entity that is creating it. The format of value will be defined in later editions of this document. T value The T characteristic specifies the type of SC. The type must be one of the following: ORD-Order SC650. OFF-Offer SC641. LIC --License SC. TRA-Transaction SC640. MET-Metadata SC620. CON- Content SC630. A value The A trait identifies the author or publisher of the SC. The author / publisher identification must be unambiguous, registered with Clearinghouse 105, or both. D value The D characteristic identifies the date the SC was created and, optionally, the time. value must be in the form yyyy / mm / dd [@ hh: mm [: ss [.fsec]] [(TZ)]], which is year / month / day @ hour: minute: second. Represents one tenth of a second (time zone). The optional part of value is enclosed in [] characters. E value The E characteristic identifies the date on which the SC expires and, optionally, the time. value must be in the same format used for the previously defined D characteristic. The expiration date / time shall be compared to the clearinghouse 105 date / time whenever possible. CCURL value The CCURL property identifies the URL of the clearinghouse 105. value must be in the form of a valid external URL. H value The H characteristic identifies the algorithm used to calculate the message digest of the part contained in the SC. An example of a digest algorithm is MD5.
A DD record is a data or partial entry record that contains information that identifies the type of part, the name of the part, the digest of the (optional) part, and the indication that the (optional) part is not included in the SC. Is. The-symbol immediately following the type identifier is used to indicate that the part is not included in the SC. The reserved types of data or partial records are: K part_name [digest]
Specify the key description part. W part_name [digest]
Specify the water marking command part. C part_name [digest]
Specifies the certificate used to verify the digital signature. T part_name [digest]
Specify the usage condition part. YF part_name [digest]
Specify the template part of offer SC641. YO part_name [digest]
Specify the template part of the order SC650. YL part_name [digest]
Specify the template part of license SC660. ID part_name [digest]
Specify the ID of the content 113 of the item of the referenced content 113. CH part_name [digest]
Clearinghouse 105 Specify the certificate part. SP part_name [digest]
Electronic Digital Content Store 103 Specify the certificate part. B part_name [digest]
Specifies the BOM part of another SC whose part or subset of parts is contained in this SC. BP part_name sc_part_name [digest]
Specifies the BOM part of another SC that is contained in this SC as a single part. The sc_part_name parameter is the name of the SC part contained in this SC and defined by this BOM part. The same BOM is also included in the SC defined by the sc_part_name parameter. D part_name [digest]
Specify the data (or metadata) part.
SS records are signature records used to define digital signatures for SCs. The digital signature is specified as follows. S key_identifier signature_string signature_algorithm The S record contains the key_identifier to indicate the encryption key for the signature, the signature_string which is the base64 encoding of the digital signature bit string, and the signature_algorithm used to encrypt the digest to create the digital signature. Is included.
C. Key description part The key description part is created by the packer to provide information about the encryption key needed to decrypt the encrypted part of the SC. The encrypted part may be included in the SC being created and in other SCs referenced by the SC being created. The key description portion is a text file containing an encryption key and a record of information about the portion in which the encryption key was used. Each record in the key description is on a single line, with a line break indicating the beginning of a new record.
The following record types are used within the key description portion and are defined as follows:
K encrypted_part_name; result_part_name; part_encryption_algorithm_identifier; public_key_identifier key_encryption_algorithm and encrypted_symmetric_key
The K record specifies the encrypted part that may be contained in this SC or in another SC referenced by this record. encrypted_part_name is either the name of this SC part or a URL that points to the name of the encrypted part in another SC. result_part_name is the name given to the decrypted part. part_encryption_algorithm_identifier indicates the encryption algorithm used to encrypt that part. public_key_identifier is the key identifier used to encrypt the symmetric key 623.
key_encryption_algorithm_identifier indicates the encryption algorithm used to encrypt the symmetric key 623. encrypted_symmetric_key is the base64 encoding of the bit string of the encrypted symmetric key 623 used to encrypt that part.
VII. Clearinghouse 105 A. Overview The clearinghouse 105 is responsible for the rights management function of the secure digital content electronic distribution system 100. The functions of the clearing house 105 include enabling the electronic digital content store 103, verifying the rights of the content 113, verifying the integrity and authenticity of purchase transactions and related information, and encrypting the content to the end user device 109. Includes distribution of keys or symmetric keys 623, tracking of distribution of these keys, and reporting of transaction summaries to Electronic Digital Content Store 103 and Content Provider 101. The content encryption key is used by the end-user device 109 to unlock the acquired content 113, typically by a purchase transaction from the authenticated electronic digital content store 103. Prior to sending the content encryption key to the end-user device 109, the clearinghouse 105 performs all verification processes to provide the authenticity of the entity that sells the content 113 and the end-user device 109 to the content 113. Verify rights. This is called the SC analysis tool 185. In some configurations, the clearinghouse 105 accounts for content 113 purchases by co-locating a system at the clearinghouse 105 that performs the functions of the electronic digital content store 103: credit card authentication and billing. It can also handle clearing. Clearinghouse 105 uses OEM packages such as ICVerify and Taxware to process credit card processing and local sales tax.
An embodiment of an electronic digital content store An electronic digital content store 103 that wants to participate as a seller of content 113 in the secure digital content electronic distribution system 100 has one or more digital content stores that supply the content 113 to the secure digital content electronic distribution system 100. Make a request to provider 101. As long as the two parties reach an agreement, there is no definitive action to make the request. After a digital content label, such as a music label such as Sony or Time-Warner, decides to allow electronic digital content store 103 to sell its content 113, the clearinghouse 105 usually emails. Will be contacted via the request to add the Electronic Digital Content Store 103 to the Secure Digital Content Electronic Distribution System 100. The Digital Content Label will provide the name of the Electronic Digital Content Store 103 and all other information that the Clearinghouse 105 may need to create a digital certificate for the Electronic Digital Content Store 103. Supply. The digital certificate is transmitted in a protected manner to the digital content label and then transferred by the digital content label to the electronic digital content store 103. The clearinghouse 105 maintains a database of digital certificates it has assigned. Each certificate includes a version number, a unique serial number, a signature algorithm, the issuer's name (for example, the name of Clearing House 105), a range of dates on which the certificate is considered valid, and the name of the electronic digital content store 103. Includes, the public key of the electronic digital content store 103, and all hash codes of other information signed using the private key of the clearing house 105. An entity with the public key 621 of the clearinghouse 105 can verify the certificate and then use the public key from the certificate to verify it.
The electronic digital content store 103 may be purchased by the end user after receiving its digital certificate created by the clearinghouse 105 and the tools needed to process the SC from the digital content label. Content 113 can be started to be provided. The electronic digital content store 103 includes its certificate and transaction SC640, and the electronic digital content store 103 uses its digital signature 643 to sign the SC. The end-user device 109 first examines the digital certificate revocation list and then uses the clearinghouse 105 public key 621 to verify the information in the digital certificate of the electronic digital content store 103. Verify that the electronic digital content store 103 is a valid distributor of content 113 on the secure digital content electronic distribution system 100. The digital certificate revocation list is maintained by the clearinghouse 105. The revocation list can be included as one of the parts in the license SC660 created by the clearinghouse 105. The end-user device 109 keeps a copy of the revocation list on the end-user device 109 and can therefore be used as part of the digital certificate verification of the electronic digital content store 103. Upon receiving license SC660, the end-user device 109 determines whether a new revocation list is included and, if so, updates the local revocation list on the end-user device 109.
B. Analysis of Rights Management Processing Order SC The clearinghouse 105 receives the order SC650 from the end user after the end user receives the transaction SC640 containing the offer SC641 from the electronic digital content store 103. The order SC650 consists of a portion containing information about the content 113 and its use, information about the electronic digital content store 103 trying to sell the content 113, and information about the end user trying to purchase the content 113. Before starting processing of the information in the order SC650, the clearinghouse 105 first ensures that the SC is actually valid and that the data it contains is not corrupted in any way. Perform some processing.
Verification The clearinghouse 105 initiates verification of the order SC650 by verifying the digital signature, after which the clearinghouse 105 verifies the integrity of parts of the order SC650. To verify the digital signature, the clearing house 105 first decrypts the content 631 of the signature itself (the signing entity is the content) using the public key 661 of the signing entity included if signed. Provider 101, electronic digital content store 103, end-user device 109, or a combination thereof). The clearinghouse 105 then calculates a digest of the SC's concatenated partial digests and compares it to the encrypted content 113 of the digital signature. If the two values match, the digital signature is valid. To verify the integrity of each part, the clearinghouse 105 calculates a digest of that part and compares it to the digest value in the BOM. The clearinghouse 105 follows the same process to verify the digital signature and integrity of the parts of the metadata and offer SC641 contained within the order SC650.
In the process of verifying the digital signature of transaction SC and offer SC641, it is also indirectly verified that the electronic digital content store 103 is authorized by the secure digital content electronic distribution system 100. This is based on the fact that the clearinghouse 105 is the issuer of the certificate. Instead, the clearinghouse 105 can successfully verify the digital signatures of transaction SC640 and offer SC641 using the public key from the electronic digital content store 103, which signs the SC. Only if the entity has ownership of the associated private key. Only Electronic Digital Content Store 103 owns the private key. Note that the clearinghouse 105 does not have to have a local database of electronic digital content stores 103. This is because the store uses the clearinghouse public key to sign the public key of offer SC641 for transaction SC640.
The store usage condition 519 for content 113 that the end user is trying to purchase is then validated by the clearinghouse 105 to ensure that this store usage condition 519 is within the constraints set in the metadata SC620. To do. Recall that the metadata SC620 is contained within the order SC650.
Key processing Processing of encrypted symmetric key 623 and water marking instructions successfully completes verification of order SC650 authenticity and integrity, verification of electronic digital content store 103, and verification of store terms of use 519. After that, it is done by the clearing house 105. The metadata SC620 portion of the order SC650 typically has multiple symmetric keys 623 encrypted using the clearinghouse 105 public key 621 located in the key description portion. Encryption of symmetric key 623 is performed by content provider 101 when metadata SC620 is created.
One symmetric key 623 is used to decrypt the watermarking instruction and the other symmetric key is used to decrypt the content 113 and the encrypted metadata. Content 113 can represent a single song or the entire collection of songs on a CD, so different symmetric keys 623 can be used for each song. The water marking instruction is contained in the metadata SC620 portion of the order SC650. Content 113 and encrypted metadata are located within Content SC630 at Content Hosting Site 111. The URL and part name of the encrypted content 113 part and the metadata part in the content SC630 are included in the key description part of the metadata SC620 part of the order SC650. The clearinghouse 105 uses its private key to decrypt the symmetric key 623 and then encrypts each of them using the public key 661 of the end-user device 109. The public key 661 of the end-user device 109 is retrieved from the order SC650. The newly encrypted symmetric key 623 is included in the key description portion of license SC660 that the clearinghouse 105 returns to the end-user device 109.
During the processing time of symmetric key 623, the clearinghouse 105 may want to make changes to the water marking instructions. In that case, after the clearinghouse 105 decrypts the symmetric key 623, the water marking instruction is modified and re-encrypted. The new water marking instruction is included as one of the parts within license SC660 returned to end-user equipment 109.
If all of the processing of the order SC650 is successful, the clearinghouse 105 returns the license SC660 to the end user equipment 109. The end-user device 109 uses the information in license SC660 to download content SC630 and access encrypted content 113 and metadata. The water marking instruction is also executed by the end user device 109.
If the clearinghouse 105 is unable to successfully process the order SC650, an HTML page is returned to the end-user device 109 and displayed in the Internet browser window. This HTML page shows why Clearinghouse 105 was unable to process the transaction.
In an alternative embodiment, if the user purchases a copy of content 113 before the publication date set for sale, license SC660 is returned without the symmetric key 623. License SC660 is returned to the clearinghouse 105 to receive symmetric key 623 on or after the publication date. As an example, content provider 101 allows the user to download the song before the release date of the new song so that the customer downloads the song before the date set by content provider 101 and downloads the song. Get ready to play. This will allow content 113 to open instantly on the publication date, without competition for bandwidth and download time on the publication date.
C. Country-Specific Parameters As an option, the clearinghouse 105 uses the domain name of the end-user device 109 and, whenever possible, the credit card billing address to determine the end-user's country location. If there are restrictions on the sale of Content 113 in the country in which the end user resides, the clearinghouse 105 shall not violate these restrictions before sending license SC660 to end user equipment 109. Guarantee. Electronic Digital Content Store 103 is also expected to participate in managing the distribution of Content 113 to various countries by performing the same inspections as Clearinghouse 105. The clearinghouse 105 performs all possible inspections if the electronic digital content store 103 ignores the country-specific rules set by the content provider 101.
D. Audit Logs and Tracking Clearinghouse 105 maintains audit logs 150 of information for each action performed during Content 113 purchase transactions and report request transactions. This information can be used for a variety of purposes, including auditing, reporting, and data mining for Secure Digital Content Electronic Distribution Systems 100.
The clearinghouse 105 also maintains the balance account of the billing subsystem 182 of the electronic digital content store 103. The pricing structure of the electronic digital content store 103 is supplied to the clearinghouse 105 by the digital content label. This information can include current specials, quantity discounts, and account deficit limits that must be imposed on Electronic Digital Content Store 103. The clearinghouse 105 uses pricing information to track the balance of the electronic digital content store 103 and ensure that the electronic digital content store 103 does not exceed the deficit limit set by the content provider 101. ..
The following actions are typically logged by the clearinghouse 105. -Request for end-user device 109 for license SC660-Credit card authorization number when clearinghouse 105 processes the claim-Distribution of license SC660 to end-user device 109-Request for reporting-Content SC630 and license SC660 End-user notification of receipt and verification
The following information is typically logged by the clearinghouse 105 for license SC660. -Date and time of request-Date and time of purchase transaction-Content ID of the item to be purchased-Identification of content provider 101-Store terms of use 519-Modification of water marking instructions-Added by electronic digital content store 103 Transaction ID 535-Identification of electronic digital content store 103-Identification of end-user device 109-End-user credit card information (if Clearinghouse 105 processes the claim)
The following information is typically logged by the clearinghouse 105 for end-user credit card verification. -Date and time of request-Amount charged to credit card-Content ID of purchased item-Transaction ID 535 added by Electronic Digital Content Store 103-Identification of Electronic Digital Content Store 103-End User Identification -End user credit card information-Permission number received from the credit card clearer
The following information is typically logged by the clearinghouse 105 when license SC660 is sent to end-user equipment 109. -Date and time of request-Content ID of the item to be purchased-Identification of content provider 101-Terms of use 517-Transaction ID 535 added by electronic digital content store 103-Identification of electronic digital content store 103-End user Identification
The following information is typically logged when a reporting request is made. -Date and time of request-Date and time of report delivery-Type of requested report-Parameters used to generate the report-Identifier of the entity that requested the report
E. Report Results The report is generated by the clearinghouse 105 using the information logged by the clearinghouse 105 during the end-user purchase transaction. The content provider 101 and the electronic digital content store 103 can request transaction reports from the clearinghouse 105 via the payment verification interface 183, thus they clear their own transaction database. Can be matched with the information logged by. The clearinghouse 105 can also supply regular reports to content providers 101 and electronic digital content stores 103.
The clearinghouse 105 defines a secure electronic interface that allows content providers 101 and electronic digital content stores 103 to request and receive reports. The reporting request SC contains the certificate assigned by the clearinghouse 105 to the entity initiating the request. The clearinghouse 105 uses this certificate and the SC's digital signature to verify that the request originated from an authorized entity. The request also includes parameters that define the scope of the report, such as duration. The clearinghouse 105 validates the request parameters so that the requester can only receive the information that it is allowed to have.
If the clearinghouse 105 determines that the reporting request SC is genuine and valid, the clearinghouse 105 generates a report, packs it into a reporting SC, and sends it to the entity that initiated the request. Some reports can be automatically generated at defined time intervals and stored in the clearinghouse 105 for immediate transmission when a request is received. The format of the data contained in the report will be defined in later editions of this document.
F. Billing and payment verification The request for content 113 can be processed by either the clearinghouse 105 or the electronic digital content store 103. When the clearinghouse 105 processes the bill for the electronic content 113, the electronic digital content store 103 separates the end user's orders into electronic merchandise and, if applicable, physical merchandise. The electronic digital content store 103 notifies the clearinghouse 105 of a transaction that includes end-user billing information and the total amount that needs to be allowed. The clearinghouse 105 accepts the end user's credit card and returns a notification to the electronic digital content store 103. At the same time that the clearinghouse 105 allows the end user's credit card, the electronic digital content store 103 can charge the end user's credit card for the physical goods to be purchased. After each electronic item has been downloaded by the end user device 109, the clearinghouse 105 is notified and can therefore charge the end user's credit card. This is done by the end user device 109 as a final step before the content 113 is made available to the end user device 109.
When the electronic digital content store 103 processes the bill for the electronic content 113, the clearinghouse 105 is not notified of the transaction until the end user device 109 sends the order SC650 to the clearinghouse 105. However, the clearinghouse 105 is notified by the end-user device 109 after each electronic item has been downloaded. The clearinghouse 105 sends a notification to the electronic digital content store 103 when notified, so that the electronic digital content store 103 can charge the end user's credit card.
G. Retransmission The secure digital content electronic distribution system 100 provides the ability to handle the retransmission of content 113. This is typically done by customer service interface 184. The electronic digital content store 103 provides a user interface that allows the end user to take one step at a time to initiate the retransmission. The end user goes to the site of the electronic digital content store 103 that purchased the content 113 item to request the resend of the content 113.
Retransmission of content 113 occurs when the end user requests a new copy of the previously purchased content 113 item because the content 113 could not be downloaded or the downloaded content 113 is unavailable. The electronic digital content store 103 determines whether the end user is eligible to retransmit the content 113. If the end user is eligible for retransmission, electronic digital content store 103 creates transaction SC640 containing offer SC641 for 113 items of content to be resent. This transaction SC640 is sent to the end user device 109 and the same steps as the purchase transaction are performed by the end user. If the end-user device 109 has a scrambled key in the key library of 113 items of content that is being retransmitted, then in transaction SC640, the end-user device 109 should delete the scrambled key. Contains information to direct.
If the clearinghouse 105 processes the accounting clearing of the content 113 purchase, the electronic digital content store 103 includes a flag in transaction SC640 that is carried to clearinghouse 105 in order SC650. The clearinghouse 105 interprets the flag of order SC650 and proceeds with the transaction without charging the end user for the purchase of content 113.
VIII. Content Provider A. Overview The content provider 101 of the secure digital content electronic distribution system 100 is a digital content label or an entity that owns the rights to the content 113. The role of content provider 101 is to prepare content 113 for distribution and make information about content 113 available to electronic digital content stores 103 or retailers of downloadable electronic versions of content 113. To provide the content provider 101 with the best security and rights control, a set of tools is provided to allow the content provider 101 to prepare its content 113 on its premises and securely package it to the SC. As a result, content 113 is protected when leaving the domain of content provider 101, is never exposed, and is not accessible to unauthorized parties. This allows Content 113 to be freely distributed over unprotected networks such as the Internet without fear of exposure to hackers or unauthorized parties.
The ultimate goal of the tool for content provider 101 is to prepare 113 of the content, such as a song or series of songs, package it in the content SC630, the information describing the song, the approved use of the song (content terms of use 517). ), And to package the song promotion information in the metadata SC620. To achieve this, we provide the following set of tools. Workflow Manager 154 Schedule processing activities and manage the synchronization that requires processing. Content Processing Tools 155 A collection of tools for controlling content 113 file preparation, including water marking, preprocessing (necessary equalization, dynamic characterization, or resampling in the case of audio examples) coding and compression. .. · Metadata assimilation and input tool 161 Used to collect content 113 descriptive information through the content provider's database 160 or a third-party database or data import file or operator intervention and provide a means of specifying content terms of use 517. A collection of tools. There will also be an interface for capturing or extracting content such as digital audio content for CDS or DDP files. Quality control tools allow you to preview the prepared content and metadata. You can make the necessary corrections to the metadata or resubmit the content for further processing. · SC Packer Tool 152 Encrypts and packages all content 113 and information, and calls the SC packer to pack it into the SC. -Content distribution tool (not shown) Distribute SC to designated distribution centers such as content hosting site 111 and electronic digital content store 103. Content promotion website 156 Store metadata SC620 for download by authorized electronic digital content store 103 and, optionally, additional promotional material.
B. Workflow Manager 154 The purpose of this tool is to schedule, track, and manage the processing activity of Content 113. The application enables multi-user access, allowing content provider 101 to schedule and status content 113 remotely within the intranet or extranet. This design allows multiple individuals to work with multiple parts of content 113 in parallel, assigning specific responsibilities to different individuals, and allowing these individuals to be scattered around the world, a collaborative process. Will also be possible.
Moving on to FIG. 11, this diagram is a block diagram of the main processes of Workflow Manager 154 corresponding to FIG. The main processing in Figure 11 summarizes the content 113 processing capabilities provided by the tools described in this section. Workflow manager 154 is responsible for supplying jobs for these processes and directing the job to the next required process when the current process is complete. This is achieved through a set of application programming interfaces (APIs) that each processing tool calls for the following purposes: -Retrieve the job to be processed next-Indicate the completion of successful processing-Indicate the completion of unsuccessful processing and the reason for failure-Supply the intermediate status of processing (only partial completion of dependent processing is required) (To be able to start the process) -Add a comment to the product that will be enabled from the specified process.
The workflow manager 154 also has a user interface, and an example of the workflow manager user interface 700 is shown in FIG. 10, which provides the following functions. -A configuration panel that allows you to specify default values and conditions that are assigned and executed at various stages of the process-Customize workflow rules and automated process flows-Job scheduling-Status query and reporting-1 Add comments or instructions about jobs related to one or more processes Job management (ie suspend, release, remove, change priority (process order))
Each process is associated with a queue managed by workflow manager 154. All processes that request a job from Workflow Manager 154 are interrupted by the Workflow Manager in a wait state if there is currently no job in the queue associated with it, or the process (tool) is interrupted. Brings back to the process all the information about the job needed to perform the process. If a process is suspended in a wait state, the process resumes when the job is placed on the queue by workflow manager 154.
Workflow manager 154 also manages the flow or order of processing based on a set of defined rules. These rules can be customized by the content provider 101 if the content provider 101 has special processing requirements or configures its own default rules. When a process reports the completion of a task assigned to it, the process notifies workflow manager 154 of this situation, which workflow manager 154 is based on predefined rules. Determines the queue where the job will be placed next.
Comments indicating special processing instructions or notifications are attached to the product at any of the processing steps, either through the programming API or manually through the workflow manager user interface 700 or the processor interface. You can also do it.
The processing of Workflow Manager 154 is performed in Java® in a preferred embodiment, but other programming languages such as C / C ++, assembler, and equivalents can be used. It should be understood that the processes described below for Workflow Manager 154 can run on a variety of hardware and software platforms. Workflow Manager 154, either as a complete system or as a component of it, includes electronic distribution such as the web, or floppy diskettes, CD-ROMs, and removable hard disk devices. It can be distributed as an application program in a computer-readable medium that is not limited to.
Moving on to FIG. 11, this diagram is a block diagram of the main processes of workflow manager 154 corresponding to FIG. The following sections summarize each process and describe the information or actions required for each process.
1. Action / Information Waiting Product Process 801 A job is placed on a particular process queue when all the information it needs is available and the job successfully completes all dependent processes. After doing. Workflow Manager 154 has a special queue used to hold jobs that are not currently available for processing due to missing information or failures that prevent the next processing. These jobs are placed on the Action / Information Waiting Product Process 801 queue. Each job in this queue is this job after the action or information it is waiting for, the last action it took, and the missing or additional information has been supplied or the required action has been successfully completed. Has a relevant situation to indicate the next process to be queued.
Completion of processing causes workflow manager 154 to inspect this queue and determine if jobs in this queue are waiting for the completion of this processing (action) or the information provided by this processing. If so, the job is placed in the appropriate processing queue.
2. New Content Request Processing 802 Content Provider 101 determines which products it wants to sell and distribute electronically (for example, a product can be a song or a collection of songs). The initial function of Workflow Manager 154 is to allow operators to identify these products and place them in the queue for New Content Request Processing 802. Content provider 101 can specify what information to prompt on the product selection interface via configuration options. Enough information is entered to uniquely identify the product. Optionally, you can request manual input of the information needed to start the audio processing phase in parallel with the metadata acquisition, including additional fields. If not supplied manually, this information can optionally be retrieved from the default configuration settings or from the content provider's database 160, which is obtained in the first stage of metadata processing with automatic metadata acquisition processing 803. Can be done. The structure and functionality of content 113 in the content provider's database 160 determines the content selection process.
If the required information is specified to perform a query to database 160 for content provider 101, the job is processed by automatic metadata acquisition process 803. In music embodiments, the genre of the product and the desired compression level and the audio PCM or audio WAV filename are specified in order to properly schedule the product for audio processing. This information can be entered as part of the product selection process or selected via a customized query interface or web browser function. Specifying this information allows the product to be scheduled for content processing.
The product selection user interface provides an option that allows operators to specify whether to publish the product for processing or hold it on hold for further information. If retained, the job is queued for new content request processing 802 and waits for the next action to complete data entry or publish the product for processing. After the product is published, workflow manager 154 evaluates the specified information to determine which process the job is ready to be passed to.
Jobs are queued in automatic metadata acquisition process 803 if appropriate information is provided to enable automated queries to database 160 of content provider 101. If the database mapping table is not configured for automatic metadata acquisition process 803, the job is queued for manual metadata entry process 804 (for more information on the database mapping table, it is automatic. See section 803 of the metadata acquisition process).
If general information required for audio processing and specific information required for water marking are specified, the job is queued for Water Marking Process 808 (the first phase of content processing). If any of the required information is missing when the job is released, the job is queued for action / information waiting product processing 801 with a status indicating the missing information.
If the situation indicates that the filename of the content 113, for example the name of the PCM or WAV file if the content 113 is audio, then this is necessary for capture (or digital extraction from digital media). It may indicate that. Audio processing requires the song file to be accessible via a standard file system interface. If the song is located on an external medium or a file system that is not directly accessible from audio processing tools, copy the file to an accessible file system first. If the songs are in digital format but on a CD or digital tape, extract them to a file system accessible from audio processing tools. After the file becomes accessible, use the Workflow Manager user interface 700 to specify or select a path and filename for the job, and as a result, all other information needed for water marking. Assuming specified, the job can be made publicly available for watermarking processing.
3. Automatic Metadata Acquisition Process 803 Automatic Metadata Acquisition Process 803 performs a series of queries to the database 160 of content provider 101 or the staging database if data is imported, in an automated manner. Try to get as much product information as possible. The automatic metadata acquisition process 803 requires the following information before it can be placed in its queue. -Database mapping table that has the appropriate information to generate a query to database 160 of content provider 101-Product information required to execute the query-Product information appropriate to uniquely define the product
Perform an automated query to database 160 of content provider 101 to get the information needed to process this content 113. For example, if content 113 is music, the information needed to perform this query is the album name, or a specific album ID or selection ID defined by the UPC (Universal Product Code) or content provider 101. There is a possibility. Some of the information obtained is designated as required. Once all the required information is available, the job is then queued for Terms of Use 805. If any of the required information is missing, the song will be queued for manual metadata input processing 804. Action / Waiting for Information If any of the jobs in the queue for product processing 801 are waiting for any of the information obtained in this step, update the status of that job and no longer wait for this information. Show that. If the job no longer has unresolved requirements, it is queued as defined below.
4. Manual Metadata Entry Process 804 The Manual Metadata Entry Process 804 provides a means for the operator to enter the missing information. Manual metadata input processing 804 has no dependencies. After all the required information has been specified, the job is queued for Terms of Use 805.
5. Terms of Use 805 Terms of Use 805 allows you to specify product usage and restrictions. Condition processing 805 may require some metadata. Upon completion of the terms of use, the job will process the metadata SC creation process unless the Monitor Publishing Process 806 option is requested or the Monitoring Publishing Process 806 option is configured as the default in the rules of Workflow Manager 154. Eligible to be queued for 807. In the above case, the job is queued in the monitor publishing process 806 . Before queuing the metadata SC creation process 807, workflow manager 154 first verifies that all the dependencies of that process are met (see below). Otherwise, the job is queued for action / information waiting product action 801.
6. Monitoring and publishing process 806 Monitoring and publishing process 806 can perform quality inspection and verification of specified information about digital content products. The monitoring and publishing process 806 has no dependency. The supervisor may review the comments previously added to the job during the processing phase of this product and take appropriate action. After reviewing all information and comments, the supervisor has the following options: -Approve the publication and queue the product to the metadata SC creation process 807-Change or add information and queue the product to the metadata SC creation process 807-Add a comment to the job and manually meta Queue data entry process 804 Add a comment and put the job in the queue of action / information waiting product process 801
7. Metadata SC creation process 807 The metadata SC creation process 807 collects all the information collected above as well as all other information needed for the metadata SC620 together and calls the SC packer process to generate the metadata SC620. create. This tool requires the following as input: -Required metadata-Terms of use-Encryption key used at all quality level encryption stages of this product
This final dependency requires the associated audio object to complete the audio processing phase before creating the metadata SC620. Upon completion of metadata SC creation process 807, the job is queued to either final quality assurance process 813 or content distribution process 814 based on the defined workflow rules.
8. Watermarking 808 Watermarking 808 adds copyright information and other information to Content 113. For embodiments where the content 113 is music, the tool requires the following as input: -Song file name (multiple file names in the case of an album) -Water marking command-Water marking parameter (information to be included in the watermark)
Upon completion of Watermarking Process 808, the job is queued for Preprocessing and Compression Processing 809 if the required inputs are available, otherwise queued for Action / Information Waiting Product Processing 801. Can be put in.
9. Pre-processing and compression processing 809 Pre-processing and compression processing 809 first performs the necessary pre-processing and encodes the content 113 to the specified compression level. Putting a job in this queue actually creates multiple queue items. Jobs are created for each desired compression level of the product. The coding process can be executed in parallel on a plurality of systems. This tool requires the following as input: -Watermarked content filenames (multiple filenames if content 113 is an album) -Product quality level (preconfigurable) -Compression algorithm (preconfigurable) -Product Genre (if required by preprocessor)
Upon completion of the coding process, the job is queued to Content Quality Control Process 810 if configured by a workflow rule. Otherwise, the job is queued for encryption processing 811.
How a third-party provider of coding tools displays the processed percentage of content 113, such as audio, or how it shows the encoded amount of content 113 as a percentage of the overall selection of selected content 113. If not provided, FIG. 14 shows a flow diagram 1100 of a method of determining the coding rate of the digital content of the content preprocessing and compression tool of FIG. The method begins with the selection of the desired coding algorithm and bit rate (step 1101). A query is then made to determine if this algorithm and code rate have a previously calculated rate factor (step 1102). The rate factor is a factor used to determine the rate of compression for a particular coding algorithm and a particular bit rate. If the previously calculated rate factor is not stored, the sample of content 113 is encoded for a predetermined length of time. The predetermined time period of the preferred embodiment is 2-3 seconds. This percentage of coding over a given time period is used to calculate the new rate factor RNEW. The calculation of the new rate factor RNEW when the length of time and the amount of encoded content 113 is known is RNEW = (length of encoded digital content) / (length of time). (Step 1108). Content 113 is encoded and the coding status is displayed using the previously calculated rate factor RNEW (step 1109). This coding rate coefficient RNEW is stored for future use with respect to this coding algorithm and code rate (step 1107). If the selected algorithm has a previously calculated rate factor RSTORED, processing proceeds to step 1103. Encode content 113 and display progress using the previously calculated rate factor RSTORED (step 1104). In the meantime, the current rate factor Rcurrent is calculated for the selected algorithm and bit rate (step 1105). Using this current rate factor Rcurrent , Update the stored rate factor to the average of RNEW = (RSTORED + Rcurrent) (step 1106). Iterative updates of the rate factor allow the determination of the code rate to be more accurate with each subsequent use of a particular coding algorithm and bit rate. Remember the new rate RNEW for future use (step 1107). If the current rate factor Rcurrent is outside the previously stored rate factor RSTORED within a given range or threshold, the RSTORED may not be updated.
In this case, a display of the coding status can be presented. The coding status includes the display of the current coding rate as well as the percentage of all content 113 displayed as a progress bar based on the coding rate and the total length of the content 113 file. The coding status can also include the remaining time of coding. The remaining coding time can be calculated by dividing the calculated coding rate Rcurrent by the total length of the content 113 file. The coding status can be transferred to another program, which can call the calling process. This can help manipulate supervisor programs for coding or programs that co-dependent on coding and batch them for more efficient processing. It should be understood that in alternative embodiments, the coding can include a step of water marking.
10. Content quality control process 810 The content quality control process 810 is similar in function to the monitoring and publishing process 806. This is an optional step that allows someone to verify the quality of the content processing performed so far. It has no dependencies other than the completion of the coded portion of the water marking process 808 and the pretreatment and compression processing 809. At the completion of content quality control process 810, the following options are available. -The job can be released and queued for encryption processing 811. -Comments can be added and one or more jobs can be requeued to preprocessing and compression processing 809.
The final option requires that the unencoded, water-marked version of the song file be available until after Content Quality Control Process 810.
11. Cryptographic processing 811 The encryption processing 811 calls the appropriate secure digital content electronic distribution right management function to encrypt each of the water marking / encoded song files. This process has no dependencies other than the completion of all other audio processes. When the encryption process 811 process is completed, the job is queued in the content SC creation process 812.
12. Content SC creation process 812 Content SC creation process The process of 812 may require that some metadata files be included in the content SC630. When files other than content 113 are required, those files are collected and the SC packer process is called to create content SC630 for each compression level of content 113 (for example, a song) to be created. Upon completion of content SC creation process 812, the song is queued to either final quality assurance process 813 or content distribution process 814 based on the defined workflow rules.
13. Final Quality Assurance Process 813 Final Quality Assurance Process 813 enables cross-reference inspection between the relevant metadata SC and content SC630 so that they are in good harmony and all the information and content contained therein. This is an optional step to verify that 113 is correct. Upon completion of final quality assurance process 813, the job is queued for content distribution process 814. If a problem is found, the job must most likely be requeued at the failed stage. Reworking at this stage is much more costly. This is because the product must undergo re-encryption and repacking in addition to the reprocessing required to fix the problem. It is highly recommended to use the previous warranty steps to ensure the quality of Content 113 and the accuracy and completeness of the information.
14. Content distribution processing 814 Content distribution processing 814 processing is responsible for transferring the SC to the appropriate hosting site. After the successful transfer of the SC, the job completion status is logged and the job is removed from the queue. If there is a problem with the SC transfer, after a defined number of retries, the job is flagged in Workflow Manager Tool 154 as unsuccessful, with any errors encountered.
15. Workflow rules The workflow rules in Figure 11 operate on three main systems: A: Workflow Manager Tool 154 1. New Content Request Processing 802 2. Action / Information Waiting Product Processing 801 3. Final Quality Assurance Process 813 4. Content Distribution (and Notification) Processing 814 B: Metadata Assimilation and Input tool 161 1. Automatic metadata acquisition process 803 2. Manual metadata input process 804 3. Monitoring and publishing process 806 4. Metadata SC creation process 807 C: Content processing tool 155 1. Water marking process 808 (copyright data is Required) 2. Pre-processing and compression processing 809 3. Content quality control processing 810 4. Encryption processing 811 5. Content SC creation processing 812
Workflow Content 113 A select operator enters a new product and it is started with it queued to A1 (New Content Request Processing 802). A1: Content 113 When the selection operator publishes the product to Workflow Manager Tool 154, the product is queued in B1 (Automatic Metadata Acquisition Process 803). A2: On the way to step Before (metadata SC creation process 807) coming from step B1 (automatic metadata acquisition process 803), step B2 (manual metadata input process 804), or step B3 (monitoring disclosure process 806) [encryption] I need a key]. On the way to either Step A3 (Final Quality Assurance Process 813) or Step A4 (Content Distribution Process 814) coming from Step Before (Metadata SC Creation Process 807) [Content SC630 Required]. On the way from step C1 (watermarking process 808) to step C2 (preprocessing and compression processing 809) [requires metadata for preprocessing and compression processing 809]. Coming from step C4 (encryption process 811) On the way to step C5 (content SC creation process 812) [Requires metadata for content SC630 packing]. On the way to either Step A3 (Final Quality Assurance Process 813) or Step A4 (Content Distribution Process 814) coming from Step C5 (Content SC Creation Process 812) [Metadata SC620 Required]. A3: After step A3 (final quality assurance process 813), queue B2 (manual metadata input process 804), queue B3 (monitoring and publishing process 806), or queue as required by the quality assurance operator. A4: After step A4 (content distribution processing 814), workflow manager tool 154 finishes for this product. B1: After step B1 (automatic metadata acquisition process 803), if step C1 (watermarking process 808) has the required metadata then put the item representing this product in queue C1. (Also perform the following logic) if 1-either one of the required metadata is missing or 2-there is a comment directed to the manual metadata supplier then queue this product B2 (manual metadata) Also put in input processing 804), else if the product was requested to be monitored and published then put in queue B3 (monitored publishing process 806), else if the product is a content processing tool for all requested quality levels 155 Then put the product in the queue Before (metadata SC creation process 807) with all the information from, flag the product as an else encryption key is needed, and queue the product to queue A2 (action / information waiting product process 801) Put in. B2: During step B2 (manual metadata entry process 804), if step C1 (watermarking process 808) is not completed and the required metadata exists in step C1 then put the item representing this product in queue C1 .. (Also perform the following logic) if Step C2 (preprocessing and compression processing 809) has just been supplied with the necessary metadata then (also executes the following logic) if metadata assimilation and input tool 161 collects All of the metadata that can be present then if put the then product requested to be monitored for this product on queue B3 (monitored publishing process 806) else if content processing tool 155 from step C4 (encryption process 811) All information is present then put this product in the queue Before (metadata SC creation process 807) else Flags the product as it requires an encryption key and puts this product on queue A2 (action / waiting for information product processing 801). else if the metadata provider requested forced monitoring publishing then put this product in queue B3 (monitoring publishing process 806) else do nothing (keep the product in queue B2 (manual metadata entry process 804)). B3: During step B3 (monitoring publishing process 806), if this operator sends the product back to step B2 (manual metadata entry process 804) then puts the product on queue B2. else if this operator publishes the product then if all information from step C4 (encryption process 811) of content processing tool 155 exists then puts this product in the queue Before (metadata SC creation process) else encryption Flags the product as it requires a encryption key and puts this product on queue A2 (action / information waiting product processing 801). else The product stays in queue B3 (monitoring publishing process 806). Before: Before: After step Before (metadata SC creation process 807), flag the product as having metadata packed if (product / quality level) SC with the configuration of content provider 101 then if all of the tuples are packed. Quality assurance is specified then Put this product in queue A3 (final quality assurance process 813) else Put this product in queue A4 (content distribution process 814). else Content 113SC flags the product as needed and puts this product on queue A2 (Action / Information Waiting Product Process 801). C1: After step C1 (watermarking process 808), if the metadata required for step C2 (preprocessing and compression processing 809) exists then (product / quality level) Create items for each tuple and put them in queue C2 Put, else Flag the product as it needs metadata for preprocessing / compression and put this product on queue A2 (action / information waiting product processing 801). C2: After step C2 (preprocessing and compression processing 809), content quality control process 810 is specified in the configuration of if content provider 101 then Queue this (product / quality level) tuple C3 (content quality control process) Put in 810), else Put this (product / quality level) tuple in queue C4 (encryption process 811). C3: After step C3 (content quality control process 810), put this (product / quality level) tuple on queue C4 (encryption process 811). C4: After step C4 (encryption process 811), provide the required information (ie, the symmetric key 623 generated by this process and used to encrypt content 113) to the metadata assimilation and input tool 161. if content SC630 has all the required metadata then put this (product / quality level) tuple on queue C5 (content SC creation process 812), else flag the product as requiring metadata for content SC630 packing Stand up and place this (product / quality level) tuple on queue A2 (action / information waiting product process 801). C5: After step C5 (content SC creation process 812), flag the quality level as having content 113 of this quality level packed if (product / quality level) metadata to the product then if all of the tuples are packed Is flagged as packed then if SC quality assurance is specified in the configuration of content provider 101 then put this product in queue A3 (final quality assurance process 813) else queue this product Place else metadata SC620 in A4 (content distribution process 814) Flags the product as needed and places this product in queue A2 (action / information waiting product process 801). else (All (product / quality level) tuples are not packed) Do nothing (another (product / quality level) tuple triggers the action).
C. Metadata Assimilation and Input Tools Metadata consists of data that describes content 113, for example, in music, the title of the recording, the artist, the author / composer, the producer, and the length of the recording. Based on Musical Content 113, those skilled in the art should understand that other content types such as video, programs, multimedia, movies, and equivalents are included in the true scope and meaning of the present invention.
This subsystem provides data that content provider 101 supplies to electronic and digital content store 103 to help promote product sales (for example, in the case of music, sample clips by this artist, biography of this artist, etc. A list of albums that contain this recording, genres related to this artist or product), data provided by Content Provider 101 to end users regarding purchased products (eg, artists, producers, album covers, track lengths), and Collect different purchasing options (Terms of Use 517) that Content Provider 101 wants to offer to end users. The data will be packed into metadata SC620 and made available to electronic digital content store 103. To achieve this, we provide the following tools. Automatic metadata acquisition tool Manual metadata input tool Terms of use tool Monitoring publication tool
These tools allow content provider 101 to perform the processes described above for workflow manager 154. The tools described herein are toolkits based on Java® in preferred embodiments, but other programming languages such as C / C ++, assemblers and equivalents can be used.
1. Automatic metadata acquisition tool The automatic metadata acquisition tool gives the user the ability to perform the automatic metadata acquisition process 803 described above. The automated metadata acquisition tool is used to access database 160 of content provider 101 and retrieve as much data as possible without the assistance of operators. A configuration method is available to automate this process. The content provider 101 adjusts the default metadata template to indicate the type of data that the content provider 101 wants to supply to the end user (eg, composer, producer, accompaniment, track length) and the content provider 101. Types of promotional data that is supplied to Electronic Digital Content Store 103 (for example, in the music example, sample clips by this artist, biography of this artist, list of albums containing this recording, genres related to this artist. ) Can be identified. The default metadata template includes data fields required by the end-user device 109, data fields that can be optionally supplied to the end-user device 109, and promotion of artists, albums, or singles. Contains a set of sample data fields for the electronic digital content store 103.
To extract template data fields from database 160 of content provider 101, an automated metadata acquisition tool can find the type of data (eg, biography of composer, producer, artist) and that data. Use a table that maps to a location within. Help each of the content providers 101 specify a mapping table for their environment.
The automated metadata acquisition tool uses the content provider 101's metadata templates and mapping tables to acquire all the data available from the content provider 101's database 160. The status of each product is updated using the result of the automatic metadata acquisition process 803. Products that lack the required data will be queued for manual metadata entry processing 804, and products that do not will be available for packing into the metadata SC620.
2. Manual metadata input tool The manual metadata input tool gives the user the ability to perform the manual metadata input process 804 described above. Manual metadata entry tools allow properly authorized operators to provide missing data. If the operator determines that the missing data is not available, the operator may add a comment to the product and request monitoring and disclosure. Content provider 101 may require the product to be monitored and published for quality assurance. After all the required data is present, the product will be available for packing into the metadata SC620 if no surveillance publication is required.
3. Terms of Use Tool The Terms of Use Tool gives the user the ability to perform the Terms of Use Process 805 described above. The process of providing Content 113 for sale or rental (restricted use) using electronic distribution involves a set of business decisions. Content provider 101 determines at what compression level content 113 is enabled. Then, one or more terms of use are specified for each of the compressed and coded versions of Content 113. Each of the Terms of Use defines end-user rights and restrictions on the use of Content 113.
As part of Content Processing Tool 155, a set of terms of use (end user rights and restrictions) is added to the product.
The terms of use define the following: 1. A compressed, coded version of Content 113 to which these Terms of Use apply. 2. Types of users included in these Terms of Use (for example, Companies, Consumers) 3. Whether these Terms of Use allow the purchase or rental of Content 113. For rental transactions: The unit of measure used to limit the duration of the rental (for example, days, views). -The number of units above the content 113 will not be played after that. For purchase transactions: · The number of playable copies that the end user is allowed to make. The types of media on which end users can make copies of them (eg CD-R (CD-Recordable), minidiscs, personal computers). 4. The time period during which a purchase / rental transaction is allowed to occur (ie, the end user is subject to the terms of this Terms of Use only after the first availability date and before the last date of availability. Can be purchased / rented below). 5. From which the end user can make this purchase (or rental) transaction. 6. Price of purchase / rental transaction under these terms of use 7. Watermarking parameters. 8. The type of event that requires notification for Clearinghouse 105.
Example of a set of terms of use Content Provider 101 can decide to test the acceptance of the North American market for the re-release of children's songs by famous children's singers during the fourth quarter of 1997. In this test, the song will be available in two different compressed coded versions: 384Kbps and 56kbps. The 384Kbps version can be purchased (and copied to a minidisc once) or rented (2 weeks), and the 56Kbps version can only be purchased (copying is not possible). The water marking order is the same for every purchase / rental, and content provider 101 wants the clearinghouse 105 to count all copies made. This should create the following terms of use:
<tables num="10"><img file="JP2005122708A_D0010.tif" /></tables>
4. Parts of Metadata SC620 The following are some of the types of data that the Metadata Assimilation and Input Tool 161 collects for inclusion in Metadata SC620. Attempts have been made to group data into SC parts by function and destination.
<tables num="11"><img file="JP2005122708A_D0011.tif" /></tables><tables num="12"><img file="JP2005122708A_D0012.tif" /></tables><tables num="13"><img file="JP2005122708A_D0013.tif" /></tables><tables num="14"><img file="JP2005122708A_D0014.tif" /></tables>
5. Monitoring and publishing tool The monitoring and publishing tool gives the user the ability to perform the monitoring and publishing process 806 described above. An individual designated by Content Provider 101 as having watch publishing authority calls a product awaiting watch publishing (ie, a product in the queue of watch publish process 806), and its content 113 and its accompanying comments. Can be inspected and any of the following can be done: Comments that approve content 113 and publish the product for a pack to metadata SC620, or make the necessary corrections, publish the product for a pack to metadata SC620, or specify the corrective action to take. And resubmit the product to the manual metadata entry process 804.
In another embodiment, after the SC is created, the SC's content 113 can be opened, inspected for integrity and accuracy, at which point final approval or refusal for publishing the product to retail channels is given or denied. There is another optional quality assurance step that can be done.
D. Content processing tools The content processing tool 155 is actually a collection of software tools used to process digital content files to make a copy of the watermarked, coded, and encrypted content. These tools leverage industry-standard digital content processing tools to enable pluggable replacement of water marking, coding, and encryption technologies as they advance. Content processing where selected industry tools can be loaded through the command line system invocation interface and parameters can be passed, or a toolkit can be provided that can invoke functions through the DLL interface. Can be automated to some extent. The front-end application for each tool queries the appropriate queue in Content Processing Tool 155 for the next available job, retrieves the required files and parameters, loads the industry standard content processing tool, and requires it. Perform various functions. If the tool does not report completion status when the task completes, a manual update to the queue may be required.
A general version of the content processing tool 155 is described, but it can be customized. Content processing tool 155 can be written in Java®, C / C ++, or equivalent software. Content Processing Tool 155 can be distributed by computer-readable means or through websites, including disks and CDs.
1. Water Marking Tool The water marking tool gives the user the ability to perform the water marking process 808 described above. This tool uses audio water marking technology to add the copyright information of the content 113 owner to the song file. The information actually written is determined by the content provider 101 and the particular water marking technology selected. This information is available from the front-end water marking tool, so that the tool can correctly pass this information to the water marking function. This is a synchronization requirement for the metadata assimilation and input tool 161 to ensure that the metadata assimilation and input tool 161 obtains this information, for example before it can process the audio file of the song. Imposing. This song will not be available for audio processing until watering information is available.
Watermarks are common to all code-coded songs created, so they are applied in the first step of audio processing. As long as the watermark can withstand the coding technique, the water marking process only needs to be done once per song.
Various water marking techniques are known and commercially available. However, front-end water marking tools have the ability to support a variety of industry water marking tools.
2. Pre-processing and compression tools The pre-processing and compression tools give the user the ability to perform the pre-processing and compression processing 809 described above. Audio coding involves two processes. Coding is basically the application of a Rossii compression algorithm to a PCM audio stream in the music content example. Encoders can usually be tuned to produce different playback bitstream speeds based on the level of audio quality required. High quality results in a large file size, and the file size can be very large with high quality content 113, so the download time for high quality content 113 can be very long and sometimes standard. A 28800bps modem can be virtually unusable.
Therefore, content provider 101 is a hi-fi enthusiast who either buys only high quality content 113 or has a fast connection with impatient or low bandwidth customers who do not want to wait hours for downloads. Various digital content qualities can be offered for download to buy the delight of both homes and high bandwidth customers.
The compression algorithm has changed in the technique for producing low bit rate reproduction of content 113. The technique depends on both the algorithm (ie, MPEG, AC3, ATRAC) and the compression level. To achieve a higher level of compression, the data is usually resampled at a lower sampling rate before being passed to the compression algorithm. Digital content is sometimes applied to some frequency equalization levels to allow for more efficient compression with less loss of fidelity, or to prevent dramatic dropouts in some frequency ranges. Adjustments or adjustments to the dynamic characteristics of the recording may be required. Content preprocessing requirements are directly related to the compression algorithm and the level of compression required. In some cases, the style of content 113 (eg, music genre) can be successfully used as the basis for determining preprocessing requirements. This is because songs from the same genre usually have similar dynamic characteristics. In some compression tools, these pre-processing features are part of the coding process. For other compression tools, the desired preprocessing is performed before compression.
In addition to downloadable audio files for sale, each song also has an LBR-coded clip that allows the song to be sampled via the Low Bit Rate (LBR) streaming protocol. This LBR coding is also the responsibility of the content processing tool 155. This clip is provided by Content Provider 101 either as a separate PCM file or as an offset and length parameter.
Similar to water marking, it is hoped that the encoding tool can be loaded via a DLL or command line system calling interface and can pass all the parameters needed for preprocessing and compression. The front-end encoding tool provides metadata assimilation and before performing audio preprocessing when, for example, the content is music and it is determined that the genre of the song is obtained from the content provider's database 160. May have synchronization requirements with input tool 161. This depends on the coding tool selected and how uncertain the genre of the song is. If content provider 101 changes the selection of encoded quality levels for each song, this information is also provided prior to the encoding step and the metadata generated by the metadata assimilation and input tool 161. Matches with.
Various high quality coding algorithms and tools are currently known. However, front-end coding tools have the ability to support a variety of industry coding tools.
Moving on to FIG. 15, a flow chart of an embodiment of the automatic metadata acquisition tool of FIG. 11 according to the present invention is shown. This process begins with the content provider 101 reading the identifier from the medium being inspected. An example of content is an audio CD embodiment. In the audio CD embodiment, UPC (Universal Product Code), ISRC (International Standard Recording Code), ISMN (International Standard Music) Number) may be available. This identifier is read by a player suitable for the content, such as an audio CD player for audio CDs, a DVD player for DVD movies, and a DAT recorder for DAT recordings and equivalents (step 1201). This identifier is then used to index database 160 for content provider 101 (step 1202). Some or all of the information required by the workflow manager process described in Figure 11 is retrieved within database 160 and other related sources (step 1203). This information can include content 113 and associated metadata. At step 1204, workflow manager 154 is started to create electronic content 113 with the additional information retrieved. It should be appreciated that it is possible to queue multiple media selections, such as multiple audio CDs, so that automated metadata acquisition tools can create a series of content 113 for electronic distribution. For example, all content 113 can be created from a series of CDs, or from selected tracks on one or more CDs that are inspected by content provider 101.
In an alternative embodiment, preprocessing parameters can be automatically retrieved from the content provider's database 160. Here, with reference to FIG. 16, a flow diagram of a method according to the present invention for automatically setting the preprocessing parameters and the compression parameters of the preprocessing and compression tools of FIG. 11 is shown. In this embodiment, the content 113 is music. In step 1301, select the music (content 113) that is encoded by the content processing tool 155. Determine the genre of the selected music (step 1302). This can be entered manually or by using other available metadata, such as additional data retrieved from the process described in FIG. Check the selected audio compression level and audio compression algorithm (step 1303). Next, a table index is performed on which compression parameters should be used in preprocessing and compression processing 809, depending on the genre, compression settings, and compression algorithm (step 1304).
3. Content quality control tool The content quality control tool gives the user the ability to perform the content quality control process 810 described above. It is an optional content processing tool that provides quality control engineers with the opportunity to review encoded and watermarked content files and approve or reject the content files based on quality judgment. .. Quality control technicians can make manual pre-processing adjustments to re-code the content until the quality is appropriate, and can also flag the song for reprocessing and add a note describing the problem. it can.
This processing step can be configured by the content provider 101 as an optional step or a required step in the content processing workflow. An additional optional final quality assurance process, 813 steps, is provided after packaging all SCs of this content (eg, each SC of a song on a CD), at which point the quality of the content encoding is tested. However, catching issues early before encryption and packaging allows for more efficient content processing. Therefore, it is highly desirable that content quality be guaranteed at this step rather than waiting for the final completion of all processing.
4. Cryptographic tool The cryptographic tool gives the user the ability to perform the encryption process 811 described above. Content encryption is the final step in content processing tool 155. Each version of the content created by the encoding tool is encrypted here. The encryption tool is a function of the SC packer. The SC packer is called to encrypt the song and returns the generated encryption key used. This key is later passed to the SC packer for use in creating the metadata SC620.
E. Content SC Creation Tool After all the metadata has been collected, the Content SC Creation Tool groups the metadata into categories based on its intended purpose. These groups of metadata are written to a file that is passed to the SC packer tool as the metadata portion of the metadata SC620. Each part (file) has its own processing requirements. After the relevant songs have been processed, encrypted, and the target destination (URL of content hosting site 111) determined, the content SC630 for content 113 is ready to be created. Content 113, which has been processed and meets all the requirements described above, is put into the packer queue of Workflow Manager 154 for the pack.
The content SC creation tool now retrieves all of the required files created by the previous step of the metadata assimilation and input tool 161 and calls the SC packer function to create the metadata SC620 and content SC630. In this process, one metadata SC620 and a plurality of contents SC630 are created for each song. For example, if the content is music, each of the audio files created during audio processing for different quality levels of the complete song will be packed into separate content SC630. The audio file created for the sample clip is passed as a metadata file and included in the metadata SC620.
F. Final Quality Assurance Tool The final quality assurance tool gives the user the ability to perform the final quality assurance process 813 described above. After all SCs have been created for the content file, the content becomes available for final quality assurance inspection. Quality assurance can be performed at various stages of the content 113 preparatory process. Content provider 101 can choose to perform quality assurance when each of the major steps is completed to avoid excessive rework later, and wait until all audio preparation processes are complete before all. You can choose to perform quality assurance all at once. If the latter is selected, quality assurance will be performed at this position upon completion of SC creation. This tool allows you to open, inspect, and play audio on each SC of a song.
The problem found requires the SC to be recreated due to the SC's internal security features, even minor text changes. To avoid unnecessary reprocessing time, use intermediate quality assurance steps to ensure the accuracy of the metadata and this particular quality assurance step, with the appropriate cross-reference between the SCs associated with this song. It is highly recommended to book for reference verification. If a problem is found, the guarantor can enter a problem description to be added to the song and put the song back in the appropriate processing queue for reprocessing. The status is updated appropriately within Workflow Manager 154 to show the status of all relevant components of the song. If no problems are found, mark or flag content 113 as ready for publication.
G. Content distribution tool The content distribution tool gives the user the ability to perform the content distribution process 814 described above. After the content 113 is approved for publication, the SC of the content 113 is queued for content distribution processing. The content distribution tool monitors this queue and performs an immediate transfer of SC files or a batch transfer of groups of SC files based on the configuration settings provided by content provider 101. Content provider 101 can optionally configure the content distribution tool to automatically keep all SCs in this queue until they are manually flagged for release. This allows content provider 101 to prepare content before the scheduled release date and retain it until, for example, wanting to publish a new song, movie, or game. The SC can also control access to content 113 based on a defined publication date, so content provider 101 does not have to actually delay the distribution of the SC, but this manual publishing option allows for this. It can be used for purposes or to control the network bandwidth required to transfer these large files.
When flagged as public, content SC630 of content 113 is transferred via FTP to the designated content hosting site 111. Metadata SC620 is transferred to content promotion website 156 via FTP. Here, the SC is staged in a new content directory for new content 113 until processing and integration into content promotion website 156 is possible.
FIG. 21 is a flow chart of an alternative embodiment for automatically retrieving additional information of the automatic metadata acquisition tool of FIG. 11 according to the present invention. This process is similar to that described in FIG. 11 above. However, the quality inspections of the monitoring and publishing process 806 and the content quality control process 810 are combined into one quality inspection called quality control 1704. A quality check is performed prior to metadata SC creation 807 and content SC creation 812. Performing a quality check before creating the SC eliminates the step of unpacking content 113 and associated metadata SC620. Further, in this embodiment, the queue of product 801 waiting for action / information is removed. Jobs are placed on specific processing queues depending on the requested action. For example, if a job requires the input of manual metadata or additional metadata, the job is placed in the manual metadata input queue. The automatic metadata acquisition 803 is also merged with the new content request and is performed before the metadata assimilation and input tool 161 and the content processing tool 155. Finally, it is important to point out that the usage condition processing 805 is entered in both the automatic metadata acquisition 803 and the manual metadata input 804. This is because many of the conditions of use can be automatically written during the 803 steps of automatic metadata acquisition.
H. Content Promotion Website Content Provider 101 most efficiently distributes information about what is available for sale via digital download and obtains the files needed by Electronic Digital Content Store 103 In order for the lever content 113 to be available for download to its customers, each content provider 101 must have a secure website to store this information. This is similar to the method currently used by some content providers 101 to make promotional content available to retailers and others who need this information. If this type of service already exists, add an additional section to the website where the Electronic Digital Content Store 103 can go to see the list of content available for sale via download. Can be done.
Content Provider 101 has full control over the design and layout of this site and is a turnkey web server solution provided as part of the toolkit for the Secure Digital Content Electronic Distribution System 100. You can choose to use. To implement its own design for this service, the content provider 101 only needs to provide a link to the metadata SC620 for the electronic digital content store 103 to access the site. This is achieved using the toolkit for the Secure Digital Content Electronic Distribution System 100. The selection process and what information is presented is at the discretion of Content Provider 101.
The metadata SC620 received from the content distribution tool via FTP into the new content directory is processed by the content promotion website 156. These containers can be opened using the SC preview tool to view or extract information from the containers. This information can be used to update HTML web pages or add information to the searchable database maintained by this service. The SC preview tool is actually a subset of the content acquisition tools used by Electronic Digital Content Store 103 to open and process the metadata SC620. See the Content Acquisition Tools section for more details. The metadata SC620 file must then be moved to a persistent directory maintained by Content Promotion Website 156.
After the metadata SC620 is integrated into the content promotion website 156, its availability will be announced. Content provider 101 may send notifications to all of the electronic and digital content stores 103 contracted each time each of the new metadata SC620 is added to the site, and also daily (or for a defined period of time). Every), a single notification of all metadata SC620 added on that day (or period) can be performed. This notification is performed via a standard HTTP exchange with the web server of Electronic Digital Content Store 103 by sending a predefined CGI string containing parameters that reference the added metadata SC620. This message is processed by the notification interface module of the electronic digital content store 103, which will be described later.
I. Content Hosting The entertainment industry produces thousands of content titles such as CDs, movies, and games each year, adding them to the tens of thousands of content titles currently available. The Secure Digital Content Electronic Distribution System 100 is designed to support all of the content titles available in today's stores.
The number of content titles that the Secure Digital Content Electronic Distribution System 100 can ultimately download to customers on a daily basis can be in the thousands or tens of thousands. For large titles, this requires a large amount of bandwidth. Computer disk space and bandwidth requirements require a scalable distributed embodiment with multiple content hosting sites 111. The system also supports customers around the world. This requires an overseas site to speed up distribution to customers worldwide.
Content hosting in the Secure Digital Content Electronic Distribution System 100 allows content provider 101 to either host its own content 113 or share a common facility or set of facilities. It is designed to be.
Content hosting in the secure digital content electronic distribution system 100 includes a plurality of content hosting sites 111 that collectively include all of the content 113 provided by the secure digital content electronic distribution system 100, and the content. Consists of multiple secondary content sites (not shown), including current hits provided by provider 101. The number of content hosting sites 111 will vary depending on the number of end users using the system. Secondary content sites host a limited number of songs, but represent a large percentage of the bandwidth used by the system. The secondary site is brought online when the volume of the primary site grows to the point of maximum capacity. Secondary sites can be located near network access points (NAPs), which helps speed up download times. Secondary sites can also be located in different geographic areas around the world to speed up download times.
Content provider 101 acts as a single content hosting site 111 with or without additional secondary content sites if it chooses to host all of content 113 on its own system. Can be done. This allows content provider 101 to build its own scalable distributed system. In another embodiment, the electronic digital content store 103 can also act as a content hosting site 111 for some content 113. This embodiment requires a special financial agreement between the electronic digital content store 103 and the content provider 101.
1. Content Hosting Site Content 113 is available via FTP or HTTP, or on tape, CD-ROM, flash, or other computer readable by the content distribution tools described in the Content Provider section of this specification. It is added to the content hosting site 111 via offline means such as content distribution in the medium. The metadata SC620 created by content provider 101 contains a field indicating the URL that locates content SC630 for this content 113. This URL corresponds to content hosting site 111. Electronic Digital Content Store 103 may change this URL in Offer SC641 if permitted by Content Provider 101. The end-user device 109 communicates with the content hosting site 111 when it wants to download the content SC630.
The end-user device 109 initiates a request for content SC630 by sending license SC660 to content hosting site 111. This is the same as the license SC660 returned by the clearinghouse 105. The digital signature of license SC660 can be verified to determine if it is a valid license SC660. If it is a valid license SC660, you can initiate the download or redirect the download request to another content hosting site 111.
2. Content Hosting Sites Provided by Secure Digital Content Electronic Distribution System 100 For Secure Digital Content Electronic Distribution System 100, the decision of which site to use to download Content 113 is made by Content SC630. Made by the primary content site that received the first request for. This site uses the following information to make this decision. -Is there a secondary content site that hosts the requested content 113 (the majority of content 113 provided by the secure digital content electronic distribution system 100 is located only at the primary site) -End-user equipment Where is the 109 geographically located (this information can be obtained from the end user device 109 when the request is initiated at the end user device 109, which is passed to the clearinghouse 105 within the order SC650). -Is a suitable secondary site running (the secondary site may be offline) What is the load on the secondary site (if the secondary site is full of activities, you can select another site with a lower load)
Perform analysis and validation of end-user requests before sending content SC630 to end-user device 109. Maintains a database of IDs of all licensed SCs used to download content 113. This database can be inspected so that the end-user device 109 only requests each part of the purchased content 113. This prevents malicious users from repeatedly accessing content hosting site 111 in an attempt to slow down content hosting site 111, and prevents unauthorized download of content SC630.
Promotion and demotion of Content 113 to the Secondary Content Site is performed on a regular basis based on customer demand for individual parts of Content 113.
Content Hosting Router The content hosting router (not shown) resides at content hosting site 111 and receives all requests from end users waiting to download content 113. The content hosting router performs a validation check against the end user's request to ensure that the end user actually purchased the content 113. A database of the status of the secondary content site, including the content 113 there and its current status, is maintained. This current situation includes the amount of activity on the site and whether the site is down for maintenance.
The only interface to the content hosting router is the license SC660 sent by the end-user device 109 when a download of content 113 is requested. License SC660 contains information indicating that the user is allowed to download Content 113.
Secondary Content Site The secondary content site (not shown) hosts the popular content 113 of the secure digital content electronic distribution system 100. These sites are geographically distributed around the world and are located near network access points (NAPs) to improve download times. These sites will be added to the system when the demand for primary content hosting site 111 approaches maximum capacity.
IX. Electronic Digital Content Store A. Overview Support for Multiple Electronic Digital Content Stores 103 Electronic Digital Content Stores 103 are essentially retailers. This is the entity that sells content 113 in the market and distributes it to customers. With respect to the distribution of Content 113, this should include digital content retail websites, digital content retailers, or companies wishing to be involved in selling electronic content 113 to their customers. These companies may sell only the electronic content 113 and may choose to add the sale of electronic products to whatever other products they are currently offering for sale. The introduction of downloadable electronic products into the service offerings of Electronic Digital Content Store 103 is through a set of tools developed for Electronic Digital Content Store 103 as part of the Secure Digital Content Electronic Distribution System 100. Achieved.
These tools are used by Electronic Digital Content Store 103 to do the following: -Acquisition of metadata SC620 packaged by content provider 101-Extraction of content 113 from these SCs for use as input to service offering creation-Downloadable content for sale Creation of offer SC641 describing 113-Processing of sales confirmation and download initiation by creating transaction SC640 and sending it to end-user device 109-Transaction log of sales of downloadable content 113 and status of each download Management Processing status notifications and transaction authentication requests Executing accounting adjustments
These tools are designed to allow flexibility in how electronic digital content stores 103 integrate the sale of downloadable electronic content 113 into their services. The tool can be used in a way that does not require this, but requires that all accounting clearings for the purchased downloadable content 113 be processed by the clearinghouse 105. These tools also allow the Electronic Digital Content Store 103 to fully serve its customers and handle accounting transactions, including promotions and bargains, on its own. These tools allow electronic digital content stores 103 to quickly integrate the sale of downloadable content 113 into their existing services. Further, the electronic digital content store 103 does not need to host the downloadable content 113 and does not need to manage its distribution. This function is performed by the content hosting site 111 selected by the content provider 101.
The tool for the Electronic Digital Content Store 103 is implemented in Java® in a preferred embodiment, but other programming languages such as C / C ++, assembler, and equivalents can be used. It should be understood that the tools described below for Electronic Digital Content Store 103 can run on a variety of hardware and software platforms. Electronic Digital Content Store 103, either as a complete system or as a component thereof, includes, but is not limited to, electronic distribution such as the web, or floppy diskettes, CD-ROMs, and removable hard disk devices. It can be distributed as an application program in a computer-readable medium.
In another embodiment, the components of the Electronic Digital Content Store 103 are part of the Programmer's Software Toolkit. This toolkit enables a predefined interface to the components of the general purpose electronic digital content store 103 and the components of the tools described below. These predefined interfaces are in the form of API or application programming interfaces. Developers using these APIs can implement any of the functionality of a component from a high-level application program. By providing APIs to these components, programmers can quickly develop customized electronic digital content stores 103 without having to recreate the functionality and resources of these components.
Electronic Digital Content Store 103 is not limited to web-based service offerings. The tools provided are used by all electronic digital content stores 103 wishing to sell this content 113, regardless of the transmission infrastructure or distribution mode used to distribute the downloadable electronic content 113 to end users. Will be done. Broadcast services delivered over satellite and cable infrastructure also use this same tool to acquire, package, and track sales of electronic content 113. Presenting electronic products for sale and distributing these offers to end users is a major variant between broadcast-based service offerings and two-point interactive web service offerings.
B. Two-point-to-point electronic digital content distribution service Two-point-to-point mainly means a one-to-one dialogue service between the electronic digital content store 103 and the end-user device 109. This usually represents an internet web-based service provided via a telephone modem connection or a cable modem connection. Networks other than the Internet are also supported by this model as long as they follow the web server / client browser model. FIG. 12 is a block diagram showing the main tools, components, and processes of the electronic digital content store 103.
1. Integration Requirements The Secure Digital Content Electronic Distribution System 100 not only creates new online businesses, but also provides a way for existing companies to integrate the sale of downloadable electronic content 113 into their current inventory. provide. The set of tools supplied to the Electronic Digital Content Store 103 simplifies this integration task. The content acquisition tool 171 and SC packer tool 153 acquire information about what the electronic digital content store 103 has available for sale from the participating content providers 101, and the electronic digital content store itself. Provides a way to create the files needed to reference these downloadable objects as inventory items. This process is batch driven, can be highly automated, and is only performed to integrate the new content 113 into the site.
A tool for secure digital content electronic distribution sells electronically downloadable content 113 in the usual embodiment of a web-based electronic digital content store 103 (ie, ColumbiaHouse online, Music). Designed to integrate into Boulevard, ower) and equivalents with minimal changes to the current content 113 retail paradigm. Multiple methods of integration are possible, and in a preferred embodiment, the electronic digital content store 103 provides search, preview, selection (shopping cart), and purchase support for all products. Each electronic digital content store 103 continues to establish its customers and customer loyalty, continue to provide its own incentives, and bring products to market, as it does today. The Secure Digital Content Electronic Distribution System 100 only needs to indicate which products in stock are also available for electronic downloads and allow customers to select electronic download options when making purchase choices. Should be. In another embodiment, the customer's shopping cart can include a mixture of electronic media selections (content 113) and physical media selections. Transaction handling of Electronic Digital Content Store 103 after the customer checks out and Electronic Digital Content Store 103 completes the checkout and logs or notifies the shipping and handling functions of the purchased physical goods. The function calls transaction processor module 175 to handle all electronic downloads. The commerce handling function simply passes the required information, and all processing from that point on is handled by the toolset for the Secure Digital Content Electronic Distribution System 100. In another embodiment, for the Secure Digital Content Electronic Distribution System 100, if the Electronic Digital Content Store 103 wants to sell only downloadable products or if it wants to separate the accounting clearing of physical and downloadable products. Other methods of transaction processing are also possible for processing accounting clearings using the tools in.
To process product downloads, the electronic digital content store 103 is given a product ID (not shown) for each downloadable product obtained from the content promotion website 156 of content provider 101. This product ID is associated with the customer's purchase choices for downloadable products. The product ID is what the electronic digital content store 103 passes to the transaction processor module 175 to identify the product purchased by the user. The SC (Offer SC641) created to describe the product is from Electronic Digital Content Store 103 to simplify the management of these objects and make their presence transparent to Electronic Digital Content Store 103. Separated and retained in offer database 181.
Transaction processor module 175 and other additional features are provided as web server-side executables (ie, CGI and NSAPI, ISAPI callable time), or simply as APIs within DLLs or C object libraries. Will be done. These features handle run-time processing for end-user interaction and interaction with the optional clearinghouse 105. These functions interact with the web server's commercial transaction service to create the files needed to initiate the download process for content 113 and download them to the end-user device 109. These features also handle optional dialogues to grant permission and accept notifications of the completion of activities.
An accounting adjustment tool 179 is also provided to assist the electronic digital content store 103 in contacting the clearinghouse 105 to adjust its accounting based on itself and the clearinghouse 105's transaction logs.
2. Content Acquisition Tool 171 Content Acquisition Tool 171 is responsible for interfacing with Content Promotion Website 156 to preview and download the Metadata SC620. Since the content promotion site is a standard website, the electronic digital content store 103 uses a web browser to navigate the site. Navigation capabilities vary based on the site design of content provider 101. Some sites offer a wide range of search capabilities with multiple screens of promotional information, while others have a simple browser interface to choose from a list of titles, performers, or new releases. All sites include a selection of metadata SC620 that contains all of the promotional and descriptive information for the song or album.
In the alternative, the electronic digital content store 103 can subscribe to the content update and automatically receive the update via FTP.
Display metadata The content acquisition tool 171 is a web browser helper application that is launched whenever the metadata SC620 link is selected on the content promotion website 156. The choice of SC causes the SC to be downloaded to the Electronic Digital Content Store 103 and launch the helper application. The content acquisition tool 171 opens the metadata SC620 and displays the unencrypted information contained therein. The information displayed includes the extracted metadata 173, in the case of music examples, graphic images related to the song and information describing the song, and if included in the metadata SC620, a preview of the song. You can also listen to the clip. In the example where content 113 is music, promotional information about the song or album, album title, and artist are also displayed if supplied by content provider 101. This information is displayed as a series of linked HTML pages within the browser window. Purchaseable content 113, such as songs and lyrics, and all other metadata that content provider 101 wants to protect will not be made accessible from retail content website 180.
In another embodiment, content provider 101 provides optional promotional content for a fee. In this embodiment, such promotional content is encrypted within the metadata SC620. The clearing of accounts to open this data can be processed through the clearinghouse 105 and the account of the electronic digital content store 103 will be charged the specified fee.
In addition to the metadata extraction preview feature, this tool provides two additional features: metadata extraction and preparation for offer SC641. When the metadata extraction option is selected, the electronic digital content store 103 is prompted to enter the path and file name to store the metadata. Binary metadata such as graphics and audio preview clips are stored as separate files. The text metadata is stored in an ASCII delimited text file, which retail content website 180 can import into its database. A table describing the layout of the ASCII delimited file is also created in another TOC file. Additional options are available that allow extraction into formats supported by other national language support (NLS).
An important part of the information provided by the extracted data is the product ID. This product ID is for the Commercial Transactions Handling feature for Electronic Digital Content Store 103 to identify user-purchased content 113 for transaction processor module 175 (see the Transaction Processing section for details). Is what you need. Transaction processor module 175 uses this product ID to correctly retrieve the appropriate offer SC641 from offer database 181 for subsequent downloads to end-user equipment 109. The electronic digital content store 103 has full control over how it offers offers for content 113 that can be downloaded on its site. The electronic digital content store 103 need only store a cross-reference to this product ID of the content 113 provided and properly interface with the tools for the secure digital content electronic distribution system 100. Providing this information here allows the electronic digital content store 103 to integrate this product or content 113 into its inventory and sales pages (database) in parallel with the offer SC641 creation process. This is because both processes use the same product ID to refer to the product. This will be described further below.
SC Packer Tool 153 for Offer SC Electronic Digital Content Store 103 needs to create Offer SC641 that describes the downloadable content 113 for sale. Most of the information written to offer SC641 is derived from metadata SC620. Content acquisition tool 171 creates offer SC641 by: · Remove parts of metadata SC620 that do not need to be included in offer SC641 according to the definition in the offer SC template of metadata SC620 · Required for electronic digital content store 103 according to the default definition specified by the configuration options in this tool Add additional parts Prompt for additional necessary input or selection according to the definition of the offer SC template of metadata SC620 Call SC packer tool 153 to pack this information into SC format.
The metadata displayed by the player application 195 (discussed in detail below) of the end-user device 109 is retained in the metadata SC620. Other promotional metadata used only by the electronic digital content store 103 as input to the electronic digital content store 103's web services database is removed from the metadata SC620. Rights management information provided by content provider 101, such as waterproofing instructions, encrypted symmetric key 623, and terms of use 517 that define the permitted use of the object, is also stored.
This stripped metadata SC620 is included in offer SC641. Electronic Digital Content Store 103 also adds to Offer SC641 its own terms of use or purchase options, referred to as Store Terms of Use 519. This can be achieved interactively or automatically through the default pair. When configured to be processed interactively, the electronic digital content store 103 is presented with a set of permitted object usage conditions 517 defined by the content provider 101. The electronic digital content store 103 selects the options it wants to offer its customers. These become the new terms of use or store terms of use 519. For automatic processing, the electronic digital content store 103 constitutes a set of default purchase options offered for all content 113. These default options are automatically checked against the permitted terms of use 517 defined by content provider 101 and set to offer SC641 if there is no conflict.
After the offer SC641 is created, the offer SC641 is stored in the offer database 181 and indexed using the pre-assigned product ID in the metadata SC620. This product ID is electronically digital to identify the downloadable content 113 purchased by the customer when later interfacing with the offer database 181 to retrieve the offer SC641 for packaging and transmission to the end user. Used by Content Store 103. See section Transaction Processor Module 175 for more information.
In another embodiment, electronic digital content store 103 hosts content SC630 at the site. In this embodiment, changes to the offer SC641 are required, such as replacing the URL of the content hosting site 111 with the URL of the electronic digital content store 103.
3. Transaction processing module 175 The electronic digital content store 103 sends the bill to the clearinghouse 105. In the alternative, the electronic digital content store 103 could request the clearinghouse 105 to settle the account directly. There are two basic modes for processing end-user purchase requests for downloadable content 113. Electronic Digital Content Store 103 does not want to process the clearing of purchases, has no special promotions or incentives to influence the sale of goods, and has a shopping cart metafa for batching purchase requests. When not in use, the electronic digital content store 103 may choose to provide a direct link to the offer SC641 file on the download page for that content 113. Offer SC641 should have been created with retail pricing information included in the metadata. Also included in Offer SC641 is a special HTML offer page that represents purchase options with duration and terms of sale. This page is created from the template created when the offer SC641 is created. When the end user clicks the direct link to offer SC641, the offer SC641 is downloaded to the browser, the end user device 109 launches the helper application, and the helper application opens its container and is included in offer SC641. Present the offer page. This page contains a form for collecting customer information, including credit card information and purchase option selection. This form is then submitted directly to the clearinghouse 105 for accounting clearing and processing. Optionally, this form can include the fields required to use the end user's credit information, or industry standard local transaction handlers.
An embodiment in which the electronic digital content store 103 processes the bill will be described below. A more typical mode of processing a purchase request is to allow the electronic digital content store 103 to process the checkout and then submit the download permission to the end user. In this way, the electronic digital content store 103 can integrate the sale of downloadable content 113 with other products offered for sale on its site, to the customer rather than to individual charges per download request. Allows batch processing of purchase requests (shopping cart metafa) with only one consolidated bill, electronic digital content store 103 directly tracks customer purchase patterns, special promotions and Be able to offer club options. In this environment, the provision of downloadable content 113 is included on the shopping page of electronic digital content store 103, and the content is as is done in the current shopping model of electronic digital content store 103. It is added to the shopping cart, processed, and cleared when selected by the end user. After the checkout is complete, the commercial transaction handling process of the secure digital content electronic distribution system 100 calls the transaction processor module 175 to complete the transaction.
Transaction Processor Module 175 The role of Transaction Processor Module 175 is to initiate the download of purchased content 113 and gather the information required by the end-user device 109 to process it. This information is packaged in transaction SC640, which is sent back to the end-user device 109 by the web server in response to the purchase submission. The transaction processor module 175 contains three pieces of information from the transaction handling process of the electronic digital content store 103: the product ID of the purchased content 113, the transaction data 642, and an HTML page or CGI URL confirming the purchase settlement. Needs.
The product ID is a value supplied to the electronic digital content store 103 within the metadata SC620 associated with the content 113 sold. This product ID is used to retrieve the associated offer SC641 from the offer database 181.
Transaction data 642 is the structure of the information provided by the transaction processing capabilities of the electronic digital content store 103, which is the accounting clearing that was later performed by the electronic digital content store 103 to process the clearing house 105. Used to correlate with transactions and provide user identification information contained in the watermark of content 113 downloaded to end-user equipment 109. When the clearinghouse 105 receives a valid order SC650, it logs the transaction and includes the content 113 sold, the electronic digital content store 103 that sold it, and the end user's name and transaction ID 535. The transaction data 642 to be executed is shown. Transaction ID 535 provides a reference to the clearing transaction. This information was later electronically digitalized by the clearinghouse 105 for use by the Electronic Digital Content Store 103 to coordinate its account with the invoice received from Content Provider 101 (or its agent). Returned to content store 103. Clearinghouse transaction log 178 allows content provider 101 to determine which content 113 has been sold and to invoice each electronic digital content store 103 for the royalties it owns. Can be used to. An electronic means other than billing can be used instead to clear the account between the content provider 101 and the electronic digital content store 103.
The information provided within transaction SC640 and the security and integrity of transaction SC640 are valid for the purchase transaction and therefore do not require further verification prior to logging this sale by the clearinghouse 105. Provides sufficient credibility for the clearinghouse 105. However, the electronic digital content store 103 is charged to its account (logged at the clearinghouse 105 indicating to the content provider 101 that the electronic digital content store 103 has collected money for the sale of this content 113). Have the option to request authentication before (of the transaction to be done). This authentication / notification request is indicated by a flag in transaction data 642. In this scenario, the clearinghouse 105 contacts the electronic digital content store 103 and receives a permit from the electronic digital content store 103 prior to billing its account and revealing the symmetric key 623. Transaction ID 535 is passed from the clearinghouse 105 to the electronic digital content store 103 as part of this authentication request, which associates this request with the previous transaction executed for the end user. You will be able to do it. The transaction ID 535 can be any unique value that the electronic digital content store 103 wants to use and is for the electronic digital content store 103 only.
Transaction data 642 also includes the customer's name. This name can be taken from the username field on the purchase form that the user fills out at the time of purchase, or from information previously logged during the user registration process with Electronic Digital Content Store 103, or the card used for this transaction. It can be the official name obtained from the credit card information associated with. This name will later be included in License Watermark 527.
Transaction data 642 also includes store terms of use 519 purchased by the end user. This information is contained in license watermark 527 and is used by end-user equipment 109 for copy and playback control.
The final parameter required by transaction processor module 175 is the HTML page or CGI URL that confirms the purchase settlement. The purpose of this is to allow the Electronic Digital Content Store 103 to return to the end user other information that it wants to include in the confirmation and response of the clearing. This HTML page or CGI URL is contained in transaction SC640 and is displayed in the browser window of end-user device 109 as transaction SC640 is received and processed.
Transaction SC640 is an HTTP response from the electronic digital content store 103 to the end user after processing the purchase submission. Sending the SC as a direct HTTP response forces the automatic loading of the SC processor helper application on the end-user appliance 109, thus automating the transaction independently of any subsequent end-user-initiated activity. Will be able to complete. This process is described in detail in Sections of End User Device 109 and Player Application 195.
Transaction processor module 175 creates and purchases transaction SC640 containing transaction data 642, transaction confirmation HTML page or reference URL and other required security features of SC when called with the required parameters. Take out and embed the relevant offer SC641. Transaction processor module 175 also logs information about this transaction for later use by notification interface module 176 and accounting adjustment tool 179.
4. Notification Interface Module 176 Notification Interface Module 176 is a web server-side executable routine (a function that can be called by CGI, NSAPI, ISAPI, or an equivalent). Notification interface module 176 handles optional requests and notifications from the clearinghouse 105, end-user equipment 109, content hosting site 111, and content provider 101. The events for which the Electronic Digital Content Store 103 can optionally request notifications are: -Notification from the clearinghouse 105 that the end-user device 109 has requested the encryption key 623 and the clearinghouse 105 is about to publish the encryption key 623 of the specified content 113. This notification can optionally be configured to require authentication from the electronic digital content store 103 before sending the encryption key 623 to the end-user device 109. -Notification from content hosting site 111 that content SC630 has been sent to end-user device 109. -Notification from end-user device 109 that content SC630 and license SC660 have been received and found to have been successfully used or corrupted in processing content 113. -Notification from content provider 101 that new content 113 has been placed on content promotion website 156.
None of these notifications are a necessary step in the Secure Digital Content Electronic Distribution System 100, but will give Electronic Digital Content Store 103 the opportunity to close the record regarding satisfaction with the completion of the sale. Therefore, it is provided as an option. These notifications may be required to process the customer service request by informing the electronic digital content store 103 of any features that have occurred since the transaction's clearing or errors that occurred during the attempt to complete the sale. Also provides some information. Instead, most of this situation can be obtained from the clearinghouse 105 via customer service interface 184, if desired.
The frequency of notification of new content 113 available on content promotion website 156 is determined by content provider 101. Notifications can be provided each time new metadata SC620 is added, or daily, for all new metadata SC620 added that day.
All of these notifications result in the creation of an entry in transaction log 178. The electronic digital content store 103 intercepts the CGI call, performs its own function, and then optionally passes the request to the notification interface module 176 if it wants to perform its own processing on these notifications. Can be done.
5. Accounting Adjustment Tool 179 This accounting adjustment tool 179 contacts the clearinghouse 105 and compares the transaction log 178 with the clearinghouse 105 log. This is an optional process that can be used to help the Electronic Digital Content Store 103 feel comfortable about the accounting of the Secure Digital Content Electronic Distribution System 100.
In another embodiment, the tool can be updated to provide electronic fund transfers for automated recurring payments to Content Provider 101 and Clearinghouse 105. The tool can also be designed to automatically process payments after adjusting the invoice for transaction log 178 when receiving an electronic invoice from the clearinghouse 105.
C. Broadcast Electronic Digital Content Distribution Service Broadcast is a one-to-many transmission method that is primarily free of personal interaction between the end-user device 109 and the electronic digital content store 103 for customizing on-demand viewing. Point to. It is typically provided via a digital satellite or cable infrastructure in which the content 113 is pre-programmed so that all end-user devices 109 receive the same stream.
Electronic Digital Content Store 103 organized in such a way that it can provide both a web distribution interface over the Internet connection and a high bandwidth satellite or cable distribution interface via a broadcast service, which has a great deal of commonality in site design. It is also possible to define a hybrid model that provides a digital content service. When the IRD backchannel serial interface is connected to the web and the IRD supports web navigation, the end user navigates the digital content service in the normal way through the backchannel internet interface. You can preview and select the content 113 to purchase. Users can select high quality downloadable content 113, purchase these selections, receive the required license SC660, all over the internet connection, and then use the high bandwidth broadcast interface. Distribution of content 113 (content SC630) can be requested via. The web service can either indicate the content 113 available for download in this form based on the broadcast schedule, or create a broadcast stream based entirely on the purchased content 113. In this way, web-based digital content services can contract with broadcast facilities to distribute high-quality content 113 to users with the right equipment, and a limited number of specific content 113 ( For example, songs or CDs) can be made available in this form daily, and the entire catalog can be made available for download via the web interface in low quality.
Other broadcast models can be designed that do not have a web interface to the end-user device 109. In this model, promotional content is packaged into a specially formatted digital stream for broadcast distribution to end-user equipment 109 (ie, IRD), which performs special processing and streams. Is decrypted, the promotional content is presented to the end user, and the purchase selection can be made from there.
The actual purchase selection should still be initiated via backchannel communication from the end user equipment 109 to the clearinghouse 105 and all data exchanges should be performed using the SC. The toolset supplied to Electronic Digital Content Store 103 was designed and developed with most tools applied to both point-to-point Internet service offerings and broadcast satellite offerings or broadcast cable offerings. There is. On the Digital Content Website of Electronic Digital Content Store 103, the tools used to acquire and manage Content 113 and prepare SCs are broadcast infrastructure by satellite-based Electronic Digital Content Store 103. It is also used to manage and prepare content 113 for distribution. The SC distributed via the web service is the same as the SC distributed via the broadcast service.
X. End User Equipment 109 The application of End User Equipment 109 for the Secure Digital Content Electronic Distribution System 100 has two main functions: first SC processing and copy control, and second encrypted content 113. Performs playback. The end-user device 109 must be able to perform these basic functions, whether it is a personal computer or a specialized electronic consumer device. The end-user device 109 also provides various additional features and functions such as creating playlists, managing digital content libraries, displaying information and images during content playback, and recording to external media devices. These features vary based on the services these applications support and the type of device on which the application is designed.
A. Overview Here, with reference to Figure 13, the main components and processes and the functional flow of the end-user device 109 are shown. An application designed to support the services of content 113 in a PC-based web interface consists of two executable software applications: the SC processor 192 and the player application 195. The SC processor 192 is an executable application configured as a helper application to the end-user web browser 191 for processing SC file / MIME types. The application is launched by the browser whenever it receives an SC from an electronic digital content store 103, a clearinghouse 105, or a content hosting site 111. This application is responsible for performing all necessary processing of the SC and ultimately adding content 113 to the end user's digital content library 196.
Player application 195 loads content 113 in its digital content library 196 for the end user to run, manage the digital content library 196, and make a copy of the content 113 if allowed. It is an independent executable application. Both player application 195 and SC processor 192 applications can be written in Java®, C / C ++, or equivalent software languages. In a preferred embodiment, these applications can be downloaded from a computer-readable means such as a website. However, other distribution mechanisms are possible, such as distribution on a computer-readable medium such as a diskette or CD.
Content 113 Searching for and browsing information, such as previewing song clips, and selecting songs for purchase, are all processed through the end-user web browser 191. The Electronic Digital Content Store 103 offers the same form of shopping experience currently offered by a number of Content 113 retail websites. The difference for end users to current web-based content 113 shopping is that downloadable content 113 objects can be selected and added to their shopping cart. If the Electronic Digital Content Store 103 has other merchandise available for sale in addition to the downloadable objects, the end user can download the physical merchandise and electronically to their shopping cart. Can have a combination of goods. The end-user device 109 of the secure digital content electronic distribution system will not be used until the end user has checked out and submitted his final purchase permission to the electronic digital content store 103. From this point on, all dialogue takes place between the web server of the electronic digital content store 103 and the browser 191 of the end-user device 109. This includes a preview of a sample digital content clip. Digital content clips are not packaged in the SC, but instead are integrated as downloadable files into the web services of Electronic Digital Content Store 103 or supplied by streaming servers. The format of the clip for content 113 is not specified by the system architecture. In another embodiment, the player application 195 can interact directly with the electronic digital content store 103 or the clearinghouse 105 or go offline using a promotional CD.
B. Application Installation Player application 195 and helper application 198 are packaged in a self-installing executable program available for download from numerous websites. The clearinghouse 105 acts as a central location for hosting master download pages on public websites. This site contains links to locations where you can download the installation package. Installation packages are available at all content hosting sites 111 to provide geographical distribution of download requests. Each of the participating Electronic Digital Content Stores 103 can also make packages available for download from that site, with only a link to the master download page of the Clearinghouse 105 public website. It can also be provided.
End users who wish to purchase downloadable content 113 will download and install this package. The installation is self-contained within this downloadable package. The package unpacks and installs both helper application 198 and player application 195, and configures helper application 198 for the installed web browser.
As part of the installation, a public / private key 661 pair is created for the end-user device 109 for use in processing the order SC and license SC660. A random symmetric key (private user key) is also generated for use in protecting the song encryption key in license database 197. The private user key (not shown) is protected by splitting the key into multiple parts and storing each part of the key in multiple locations throughout the end user's computer. The area of this code is protected using anti-tamper software technology to ensure that the key is segmented and where it is stored is not leaked. Making this key inaccessible even to the end user helps prevent piracy or sharing of Content 113 with other computers. See section SC Processor 192 for more information on how to use these keys.
Anti-tamper software technology is a way to prevent unauthorized intrusion by hackers into computer software applications. Hackers usually want to understand and modify the software to remove restrictions on its use. In reality, there are no computer programs that cannot be hacked, so tamper-resistant software is not called "tamper-proof." However, the amount of effort required to hack a tamper-protected application usually does not deserve the possible benefits of that effort, thus blocking most hackers. In this case, the effort would be to gain access to the key to a portion of content 113, perhaps only one song on the CD.
One type of anti-tamper software technology is provided by IBM. One of the products that introduced this code is the IBM ThinkPad 770 laptop computer. In this case, anti-tamper software was used to protect the DVD movie player in the computer. Digital content providers, such as Hollywood Studios, were concerned about the advent of digital movies and the ease with which they could make perfect copies, and insisted on including a copy protection mechanism in movies on DVD discs. IBM's anti-tamper software makes it difficult to bypass these copy protection mechanisms. This is a very typical application of anti-tamper software. This software is used to enforce rules on the use of some protected types of Content 113.
IBM's anti-tamper software puts multiple types of obstacles in the attacker's path. First, it includes techniques that allow hackers to use standard software tools, namely debuggers and assemblers, or at least reduce their effectiveness. Second, it includes self-maintainability testing, which results in detection of a single change or even a small number of changes, causing fraud. Finally, this includes ambiguities that mislead hackers in their true behavior. The latter technique is primarily ad hoc, but the first two are based on well-known tools in cryptography: cryptography and digital signatures.
C.SC Processor 192 When an end user submits a final purchase permit to an electronic digital content store 103 for items collected in a shopping cart, the end user's web browser waits for a response from the web server. Stay active. The web server of the electronic digital content store 103 processes the purchase, performs the checkout, and then returns the transaction SC640 to the end-user device 109. The SC processor 192 (helper application 198) is launched by a web browser to process the SC MIME type associated with transaction SC640. FIG. 17 is an example of a user interface screen of player application 195 according to the present invention that downloads content to a local library as described in FIG.
SC processor 192 opens transaction SC640 and extracts the response HTML page and offer SC641 contained therein. The response HTML page is displayed in the browser window to confirm the end user's purchase. The offer SC641 is then opened and the name of the content 113 (eg song or album) is extracted from it along with the estimated download time (step 1401). A new window with this information is then displayed, giving the end user the option to schedule the download of content 113 (for example, in the case of music, the song or the entire album) (step 1402). The end user can choose to download immediately or schedule the download at a later time. If a later time is selected, the download schedule information will be stored in the log and the download will start at that point if the end-user device 109 is powered on at the scheduled time. If the computer is not active or the communication link is not active at the scheduled download time, the end user will be prompted to rescheduling the download the next time the computer is turned on.
When the scheduled download time arrives or an immediate download is requested, SC processor 192 creates an order SC650 from the transaction SC640, offer SC641, and end-user public key 661 information generated during installation. .. This order SC650 is sent to the clearinghouse 105 via an HTTP request. When the clearinghouse 105 returns license SC660, helper application 198 is called again to process license SC660. The license SC660 is then opened and the URL of the content hosting site 111 is extracted from the referenced order SC650. The license SC660 is then sent to the designated content hosting site 111 via an HTTP request via a browser to request the download of content SC630. Helper application 198 is called again when content SC630 is returned to the browser. The SC processor 192 displays the name of the content 113 being downloaded, along with a download progress indicator and an estimated completion time.
While the content 113 is being received by the SC processor 192, the SC processor 192 loads the data in the content 113 into the memory buffer for decoding. The size of the buffer depends on the requirements of the encryption algorithm and water marking technology 193 and is the smallest possible size to reduce the amount of unencrypted content 113 exposed to hacker code. When the buffer is full, it is decrypted using the end-user key 623 (corresponding to public key 661) extracted from license SC660, and the key 623 itself is first decrypted using the private key. There is. The decrypted buffer is passed to the water marking function.
Watermarking 193 extracts a watermarking instruction from license SC660 and uses the end user's private key to decrypt the instruction. After that, the name of the purchaser registered in the electronic digital content store 103 from which this content 113 was purchased, or the purchase derived from the credit card registration information if the electronic digital content store 103 does not provide the registration function. Watermarking data, including transaction information such as the person's name, is extracted from license SC660. The watermark, date of purchase and, the electronic digital co to refer to specific records logged for the transaction the transaction ID535 assigned by content shop 103 are also included. Shop Terms of Use 519 are also included for copy-controlled use of Player Application 195.
Watermarking 193 is protected using anti-tamper code technology to prevent leakage of watermarking instructions, thus preventing hackers from discovering watermark locations and techniques. This prevents hackers from removing or modifying the watermark.
After writing the required watermark to this content buffer, pass the buffer to the scrambler for re-encryption 194. Re-encrypt content 113 with a random symmetric key using a processor-efficient secure encryption algorithm such as IBM's SEAL encryption technology. After the download, decryption and re-encryption 194 process is complete, the encryption key 623 that content provider 101 first used to encrypt content 113 is destroyed and a new SEAL key itself is created during installation. And encrypted using the hidden private user key. This newly encrypted SEAL key is stored in license database 197.
Unlike content providers 101 and sources that run on users, user water markings that run on end-user equipment 109 may require industry standards to be in effect. These standards are still evolving. Technology is available that embeds control information in music and allows it to be updated multiple times. Until the time when copy control standards become more stable, alternative methods of copy control will be provided within the Secure Digital Content Electronic Distribution System 100, and as a result, this system will provide rights management in consumer equipment. It will no longer depend on copy control watermarks. Security of storage and replay / record usage conditions is enforced using encrypted DC library collection 196, which is constrained to end-user equipment 109 and protected through a tamper resistant environment. Software hooks are in place to support copy control water marking when standards are adopted. Support for watermarking AAC and other encoded audio streams at various compression levels currently exists, but this technology is still somewhat unusable at this time as the only method of copy control. It is mature.
The decryption and re-encryption 194 process ensures that the original content 113 encryption key, the new SEAL key, the secret user key, the location where the secret user key segment is stored, and the method of segmenting the key are not leaked. Another area of the cord that is protected using tamper-resistant cord technology.
The process of decryption and re-encryption 194 serves two purposes. Storage of content 113 encrypted using algorithms such as SEAL can be faster than real-time decryption and has much lower processor utilization than more industry standard algorithms such as DES to perform decryption. Needs. This allows player application 195 to perform real-time parallel decryption-decryption-playback of content 113 without having to first decrypt the entire file of content 113 prior to decryption and playback. The efficiency of the SEAL algorithm and the highly efficient decryption algorithm not only allow parallel operation (streaming playback from encrypted files), but also allow processors with much lower processing power to do this. Also. Therefore, this application can be supported on 60MHz Pentium® systems and perhaps lower low-end end-user equipment 109. Separating the encryption format in which the content 113 is finally stored from the original encryption format allows greater flexibility in choosing the original content encryption algorithm. Therefore, widely accepted and proven industry standard algorithms can be used, thus further enhancing the acceptance of the secure digital content electronic distribution system 100 in the digital content industry.
The second purpose of this decryption and re-encryption 194 process is to use the original master encryption key 623, which was used by content provider 101 to encrypt this content 113, with the licensed end of this content 113. This is to eliminate the need to store in all of the user equipment 109. The encrypted master key 623 is only cached on the hard disk of the end-user device 109 for a very short time as part of license SC660, and in plaintext it is only in memory for a very short time. .. During this execution phase, key 623 is protected via anti-tamper coding technology. By eliminating the need to store this key 623 in the end-user device 109 in any way after the decryption and re-encryption 194 phase is complete, the potential for piracy by hackers is greatly reduced.
The song is re-encrypted and then stored in the digital content library 196. All metadata required for use by player application 195 is extracted from the associated offer SC641 and also stored in digital content library 196 (step 1403). Encrypted parts of the metadata, such as lyrics, are decrypted and re-encrypted in the same way as described above for other content. The same SEAL key used to encrypt content 113 is used for the associated metadata that requires encryption.
D. Player Application 1951. Overview Secure Digital Content Electronic Distribution Player Application 195 (referred to here as Player Application 195) is a CD player, DVD player, or other digital content player and a CD, Similar to both DVDs, or other digital content storage management systems. At the simplest level, player application 195 performs content 113, such as playing a song or video. At another level, player application 195 provides end users with tools to manage their digital content library 196. Equally important, player application 195 provides editing and playback of a collection of content, such as songs (referred to herein as a playlist).
The player application 195 is assembled from a set of components that can be individually selected and customized to meet the requirements of content provider 101 and electronic digital content store 103. A general-purpose version of the player will be described, but customization is possible.
With reference to FIGS. 18 and 19, a block diagram of the main components and processes of the player application 195 running on the end-user device 109 of FIG. 13 is shown.
There are multiple sets of components that make up the subsystem of Player Object Manager 1501. 1. End-user interface component 1509 2. Copy / playback management component 1504 3. Decryption 1505, decompression 1506, playback component 1507, and recording can be included. 4. Data Management 1502 and Library Access Component 1503 5. Inter-Application Communication Component 1508 6. Other (Installation, etc.) Components Components from each of these sets can be selected based on the following requirements: -Platform (Windows (registered trademark), Unix (registered trademark), or equivalent) -Communication protocol (network, cable, etc.)-Content provider 101 or electronic digital content store 103-Hardware (CD, DVD, etc.)- Clearinghouse 105 Technology Other
The sections below detail the different sets of components. The final section details how to collect these components within a general purpose player and describes how to customize these components.
In another embodiment, the components of player application 195 and SC processor 192 are available as part of the programmer's software toolkit. This toolkit enables the predefined interfaces to the components of the generic player applications listed above. These predefined interfaces are in the form of API or application programming interfaces. Developers using these APIs can implement any functionality of a component from a high-level application program. By providing APIs to these components, programmers can quickly develop customized player applications 195 without having to recreate the functionality and resources of these components.
2. End User Interface Components 1509 This set of components are combined to provide an on-screen display of player application 195. Note that the design does not establish a definitive layout for these components. One such layout is provided by a general purpose player. Alternative layouts are possible based on the requirements of Content Provider 101 and / or Electronic Digital Content Stores and / or other requirements.
This set is first divided into a subgroup of components used to present the end-user display 1510 and handle controls called end-user controls 1511 used for low-level features such as audio playback and metadata presentation. Grouped. The end-user view 1510 is then further divided by special function groupings (playlists, digital content libraries) and then by the object container components used to group and deploy these low-level components. It is divided.
In the list of components below, references to creating a CD or copying Content 113 to a CD or other recordable medium apply only if Player Application 195 has such functionality enabled. Will be done. It should also be noted that the term CD in that context is a comprehensive term and can also represent various other external recording devices such as minidiscs or DVDs.
FIG. 20 is a diagram showing a user interface screen of an example of the player application 195 of FIGS. 18 and 19 according to the present invention. Features of the end-user control 1511 include: (corresponding screens of the end-user interface are shown by reference numerals 1601 to 1605).
Controls for executing content 113-Play / Stop button-Play button-Stop button-Pause button-Skip front button-Skip back button-Volume control-Track position control / display-Audio channel volume level Display and others.
Controls for displaying metadata related to Content 113-Cover Picture Button-Cover Picture Object-Artist Picture Button-Artist Picture Object-Track List Button-Track List Information Object- Track list selector object (click to play) -Track name object-Track information object-Track lyrics button-Track lyrics object-Track artist name object-Track credit button-Track credit object-CD name object -CD credit button-CD credit object-General purpose (configurable) metadata button-General purpose metadata object etc.
Features of the end-user display 1510 include: (corresponding screens of the end-user interface are shown by reference numerals 1601 to 1605).
Display container playlist-Playlist management button-Playlist management window-Digital content search button-Digital content search definition object-Digital content search submit button-Digital content search result object-Selected search result item Copy to playlist-Button-Playlist object (editable) -Playlist save button-Playlist play button-Playlist pause button-Playlist restart button-Create CD from playlist button Others.
Display of Digital Content Library 196 Digital Content Library Button Digital Content Librarian Window Digital Content Category Button Digital Content Category Object Artist Button Genre Button Buttons by label Buttons by category Delete button Button to add to playback list Copy to CD button Song list object Song list display container Others
Container Others-Player window container-Audio control container-Metadata control container-Metadata display container-Toolbar container object-Sample button-Download button-Purchase button-Record button-Player name object Label / Provider / Store Advertising Object Label / Provider / Store URL Button Artist URL Button Others
3. Copy / Playback Management Component 1504 These components handle encryption key setup, watermarking, copy management, and more. There are also interfaces for communication with the clearinghouse 105, sending purchase requests, and other special services such as when each access to pay-per-listening or content 113 is accounted for. Currently, the function of communication to the clearinghouse 105 is handled by the SC processor 192.
The use of content 113 by player application 195 in end-user device 109 is logged in a database such as license database 197. Tracking each use of Content 113 by Player Application 195, one or more logs, such as a clearinghouse 105 or content provider 101 or an electronic digital content store 103 or a site coupled to a designated transmission infrastructure 107. It can be sent to the recording site. This transmission can be scheduled at a predetermined time for uploading usage information to the logging site. One of the expected times is early in the morning when the transmission infrastructure 107 may not be very congested with network traffic. A player application 195 using a known technique wakes up at a scheduled time and sends information from the local logging database to the logging site. By reviewing the information on the logging site, content provider 101 can measure the popularity of content 113.
In another embodiment, the use of Content 113 is uploaded to the logging site during use of Content 113, rather than logging the use of Content 113 for later uploading to the logging site. For example, its use when copying or copying content 113 stored on end-user device 109 to an external device such as a DVD disc, digital tape, flash memory, minidisc, or equivalent readable and removable medium. However, it will be an update to the logging site. This can be a prerequisite for a copy of Content 113 under Terms of Use 206 sent when purchasing Content 113. This ensures that Content Provider 101 can accurately track the use of Content 113 during playback, duplication, or other action on Content 113.
In addition, other information about content 113 can be uploaded to the logging site. For example, the last time Content 113 was executed (for example, the date and time), the number of times Content 113 was executed, and Content 113 was duplicated or copied to an authorized external device such as a DVD disc, digital tape, or minidisc. Whether or not it was. If there are multiple distinct users of a single player application 195 in end-user device 109, such as family members, the user identification of content 113 may be sent to the logging site along with usage information. it can. By reviewing the usage information uploaded to the logging site, Content Provider 101 may measure the popularity of Content 113 based on actual usage, user identification, and the number of times Content 113 has been performed. it can. By measuring actual usage, the system can be used in systems that use sampling methods, such as the Nielsen ratings system for television or telephone surveys, where only a limited number of users are sampled at 1 o'clock and the results are extrapolated. On the other hand, it becomes more fact-driven. In this embodiment, the actual use can be a measurement for a user who has logged on to a designated website such as Electronic Digital Content Store 103 or Content Provider 101.
4. Decompression 1505, decompression 1506 and playback component 1507 These components unlock the audio data acquired from the data management and library access components using the key acquired by the copy / playback management component. Then apply the appropriate decompression to prepare the audio data for playback and use the system audio service to play it. In an alternative embodiment, the audio data obtained from the data management and library access components can be copied to a removable medium such as a CD, diskette, tape, or minidisc.
5. Data Management 1502 and Library Access Components 1503 These components are used to store and retrieve song data to various storage devices on the end user's system and to process requests for information about the stored songs. ..
6. Inter-application communication component 1508 These components are the player of the secure digital content electronic distribution system and any application (eg browser, helper application, plug-in, etc.) or player that may launch player application 195. Used to coordinate with other applications that application 195 needs to use when performing its functions. For example, when a URL control is activated, it calls the appropriate browser and tells that browser to load the appropriate page.
7. Various other components Individual components (eg installations) that are not in the above category are included in this group.
8. General-purpose player This section describes the combination of the above components for a version of the player application 195. This is just one of many different examples, as the player application 195 is designed for customization based on software objects. Player Object Manager 1501 is a software framework that holds all other components together. As mentioned in the section above, the block under the Player Object Manager 1501 in this figure is required for every player, but the encryption or scrambling format used, the type of audio compression, It can be replaced with a specialized version depending on how the content 113 is accessed in the library.
Above the player object manager 1501 is the changing object 1512, which is mostly derived from the metadata associated with the content 113 being played or retrieved. These changing objects are made available to the end user device 109 by the end user display 1510 and the input received from the end user control 1511. All objects are configurable and the layout of all containers is customizable. These objects can be implemented in C / C ++, Java®, or any other equivalent programming language.
How to use player application 195 The following embodiment is an example in which the player application 195 running on the end-user device 109 is an audio player and the content 113 is music. It will be appreciated by those skilled in the art that other types of content 113 can be supported by the player application 195. Ordinary audiophiles have a library of CDs that hold songs. All of these are available within the Secure Digital Content Electronic Distribution System 100. The set of songs purchased from the electronic digital content store 103 is stored in the digital content library 196 of the end user's system. A grouping of songs that resembles a physical CD is stored as a playlist. In some cases, playlists accurately emulate a CD (for example, all tracks on a commercial CD are purchased from Electronic Digital Content Store 103 as an online version of the CD and are equivalent to the playlist on that CD. (If defined by a playlist of). However, most playlists are collected by the end user to group songs stored in the end user's system's digital content library. However, in the discussion below, we will use the example of a custom-made music CD when using term playlists.
When the end user explicitly launches player application 195 instead of launching player application 195 through a call from the SC processor 192 application, player application 195 displays the last accessed playlist. Load in advance. If the playlist does not exist in Digital Content Library 196, the playlist editor is automatically started (unless the user has turned this feature off via preference). See the playlist below for more details.
The player application 195 can also call a specific song as an argument, in which case the player application 195 immediately enters the song playback mode. As an option, the song is prepared to be played, but it can proceed after waiting for the end user to perform the action. For more information on this situation, see the Song Play section below.
Playlist (corresponding to screen 1603 of the end user interface) When the end user calls the playlist function, the functions that can be used are as follows. -Open playlist-Call a digital content librarian to display a list of stored playlists for selection. See also the Digital Content Librarian section below for more information. -Edit playlist-Call the playlist editor (see below). If the playlist is already loaded, load the current playlist. If not, the editor creates an empty playlist. -Run playlist-Songs are played one at a time, starting with the selected song (or at the beginning of the playlist if no song is selected). The options set in the playlist editor affect the playback order. However, here are the controls available to change this playback option in the playlist. -Play a song-Play only the song selected from the playlist. See the song playback section below for details. -Playlist information-Display information about playlists. -Song information-Displays information about the song selected in the playlist. -Visit website-Load the website related to this playlist into your browser. -Librarian-Opens the Digital Content Librarian window. See also the Digital Content Librarian section below for more information.
Playlist Editor (corresponding to screen 1603 of the end user interface) When the playlist editor is launched, the end user options are as follows. -Show / load / delete playlists-Digital Content Lively Run is called to display a list of stored playlists for selecting playlists to load or delete. See also the Digital Content Librarian section below for more information. -Save playlist-Save the current version of the playlist in Digital Content Library 196. -Delete song-Delete the currently selected song from the playlist. -Add song-A digital content librarian is called in song search mode to select a song to add to the playlist. See also the Digital Content Librarian section below for more information. Song information settings -Display information about the song selected in the playlist and allow changes to that information. This information is stored in the playlist and the information about the songs stored in the digital content library 196 is unchanged. The following items can be changed. Title of the displayed song End user's memo about the song Lead-in delay during song playback Follow-on delay after song playback Start point in the song during playback End point in the song during playback Random Weighting for mode Volume control of this song etc.
Playlist attribute settings: Show the attributes of this playlist and allow changes to them. The following attributes can be set. -Playlist title-Playlist mode (random, sequential, etc.)-Repeat mode (play once, resume at end, etc.)-End user notes about this playlist
Librarian (corresponds to end-user interface screen 1601) -Opens the Digital Content Librarian window. See also the Digital Content Librarian section below for more information.
Playing a song The song is ready for playback, either by calling player application 195 with the song as an argument, or by selecting a song to play from within the playback list or digital content librarian. At that time, the end-user options are as follows (corresponding to screen 1601 of the end-user interface). -Play-Pause-Stop-Skip backward-Skip forward-Volume adjustment-Track position adjustment-Lyrics display-Credit display-CD cover display-Artist / picture display-Track information display-Other metadata display- Visit websites Playlists Librarians and others
Digital Content Librarian A digital content librarian can be called implicitly when selecting a song or playlist (see above) or in its own window for managing the song library on the end user's system. Can be opened with. In that case, the end-user options are: Song Manipulation: Sort everything by artist, category, label, etc. Select songs by artist, category, label, etc. Add selected songs to current playlist Copy songs to CD (enabled) If you have) Delete songs Add songs to categories Other Playlist operations: Sort by name Sort by category Search by keyword Search by title of included songs Load selected playlists Playlist Rename to Delete Playlist Create a CD from the selected playlist (if enabled) Other
The contents of the present invention are collectively disclosed below. (1) An electronic content management system including a clearing house that enables secure provision of data, wherein the clearing house can communicate with a data system in order to provide data safely. The data system can receive both the data encrypted using the first encryption key and the encrypted first encryption key, and the encrypted first encryption key is the first. 2 The first encryption key encrypted by the encryption key, and the clearing house decrypts the first decryption key from the encrypted first decryption key and the decrypted first decryption key. An electronic content management system, including the transfer of data to a data system. (2) The data system is a means for encrypting data with a first encryption key in order to generate encrypted data, and a second for generating an encrypted first decryption key. A means for encrypting the first decryption key with an encryption key, a means for transferring the encrypted data to the second system, and a means for transferring the encrypted first decryption key to the second system. , The management system according to (1), which includes a means for transferring the encrypted first decryption key to the clearinghouse that owns the second decryption key. (3) The means for transferring the first decryption key to the second system further includes means for re-encrypting the first decryption key with the third encryption key before the transfer of the first decryption key. The management system according to (2), which is a means for transferring the decrypted and re-encrypted first decryption key to the second system. (4) The management system according to (3), wherein the third encryption key is the public key of the second system. (5) The management system according to (2), wherein the second encryption key is the public key of the clearinghouse, and the second decryption key is the corresponding private key of the clearinghouse. (6) The management system according to (2), further comprising means for confirming that the data has been paid for it. (7) The management system according to (2), further comprising means for permitting the transfer of the data before transferring the encrypted data decryption key to the second system. (8) A system that manages content data, related metadata, and related terms of use data. Transfer the metadata and terms of use data for the relevant content data, the means of modifying at least one portion of the metadata and the terms of use data to create the promotional data, and the promotional data. A system that includes means and. (9) The content data includes music data, the usage condition data limits the number of times the music data can be played, the maximum number of copies of the music data that can be made, and the music data is played. The system according to (8), which includes at least one of the maximum number of times that can be done. (10) The content data includes music data, the metadata includes a link to a content data host, a description of the content of the music data, artwork related to the music data, and the music data. The system according to (8), which comprises at least one of the selected parts of. (11) Content providers that can send content data related metadata and content data related terms of use data, and The system according to (8), further including an electronic store, capable of receiving the metadata and the terms of use data from the content provider and creating the sales promotion data. (12) The content provider further encrypts the content using the first encryption key, encrypts the first encryption key using the second encryption key, and encrypts the encrypted first encryption. The system described in (11), which is capable of transmitting keys. (13) The content data includes music data, the usage condition data limits the number of times the music data can be played, the maximum number of copies of the music data that can be made, and the music data is played. The system according to (11), which includes at least one of the maximum number of times that can be done. (14) The content data includes music data, and the transmitted metadata includes information identifying the content provider, a link to the content host, a description of the content of the music data, and the music data. The system according to (11), comprising artwork related to, and at least one of at least one of the selected parts of the music data. (15) The content provider can transmit the content data, and the system further includes a content host capable of receiving the content data from the content provider, according to (11). System. (16) A digital content data player that reproduces digital content data, wherein the data player includes a transmitter that transmits usage information, and the usage information is recorrection or correction of the digital content data. Identification of the occurrence of a copy, the number of times the digital content data has been rectified or copied, when the digital content data has been rectified or copied, and the user who has rectified or copied the digital content data. A digital content data player, at least one of them. (17) The data player according to (16), wherein the digital content data includes digital music data. (18) A system that tracks the use of digital content, with licenses to rectify or copy digital content data, and licensed digital content data. The occurrence of rectification or copying of the licensed digital content data, the number of times the licensed digital content data has been rectified or copied, and the number of times the licensed digital content data has been rectified or copied. A system that contains information about when is rectified or copied, and at least one of the identifications of the user who rectified or copied the licensed digital content data. (19) The system according to (18), further comprising prohibiting further rectification or copying based on the above information. (20) The system according to (18), wherein the digital content data includes digital music data. (21) The system according to (18), wherein the information is transmitted at a predetermined time or at a predetermined interval. (22) A computer-readable medium containing program instructions that track the use of digital content data on the user's equipment, with instructions to obtain a license to correct or copy the digital content data, and the license issued. Instructions to accept digital content Reproduction of the digital content data, copying of the digital content data, when the digital content data is rectified or copied, and identification of the user who rectified or copied the digital content data. A computer-readable medium that contains instructions that send information about at least one of them.
<figref num="1">It is a part of the block diagram which shows the outline of the secure digital content electronic distribution system by this invention.</figref><figref num="2">It is a part of the block diagram which shows the outline of the secure digital content electronic distribution system by this invention.</figref><figref num="3">It is a part of the block diagram which shows the outline of the secure digital content electronic distribution system by this invention.</figref><figref num="4">It is a part of the block diagram which shows the outline of the secure digital content electronic distribution system by this invention.</figref><figref num="5">FIG. 6 is a block diagram showing an example secure container (SC) and associated graphical representation according to the present invention.</figref><figref num="6">It is a block diagram which shows the outline of the encryption process of the secure container (SC) by this invention.</figref><figref num="7">It is a block diagram which shows the outline of the encryption processing of a secure container (SC) by this invention.</figref><figref num="8">It is a block diagram which shows the outline of the layers of the rights management architecture of the secure digital content distribution system of FIGS. 1 to 4 according to the present invention.</figref><figref num="9">It is a block diagram which shows the outline of the content distribution and license issuance control applied to the license control layer of FIG.</figref><figref num="10">It is a figure which shows the user interface of the example of the workflow manager tool of FIGS. 1 to 4 according to this invention.</figref><figref num="11">It is a block diagram of the main tools, components, and processes of the workflow manager corresponding to the user interface of FIG. 10 according to the present invention.</figref><figref num="12">FIG. 6 is a block diagram showing the main tools, components, and processes of the electronic digital content store of FIGS. 1 to 4 according to the present invention.</figref><figref num="13">It is a block diagram which shows the main component and processing of the end-user apparatus of FIGS. 1 to 4 according to this invention.</figref><figref num="14">It is a flow chart of the method of calculating the code rate coefficient of the content preprocessing and compression tool of FIG. 11 according to the present invention.</figref><figref num="15">It is a flow chart of the method of automatically extracting additional information of the automatic metadata acquisition tool of FIG. 11 according to the present invention.</figref><figref num="16">It is a flow chart of the method of automatically setting the pre-processing parameter and the compression parameter of the pre-processing and compression tool of FIG. 11 according to this invention.</figref><figref num="17">FIG. 5 shows an example of a user interface screen of a player application that downloads content to a local library as described in FIGS. 18 and 19 according to the present invention.</figref><figref num="18">FIG. 3 is a block diagram showing the main components and processes of a player application running on the end-user device of FIG. 12 according to the present invention.</figref><figref num="19">FIG. 3 is a block diagram showing the main components and processes of a player application running on the end-user device of FIG. 12 according to the present invention.</figref><figref num="20">It is a figure which shows the user interface screen of the example of the player application of FIG. 18 and FIG. 19 according to the present invention.</figref>
35 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35
100 members in 13 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 09133519 | United States of America | – | |
| 13351998 | United States of America | A | |
| 13351998 | United States of America | A | |
| 09177096 | United States of America | – | |
| 17709698 | United States of America | A | |
| 17709698 | United States of America | A | |
| 1998133519 | – | – | – |
| 1998177096 | – | – | – |
| US19980133519 | – | – | – |
| US19980177096 | – | – | – |
Members100
| Document | Office | Kind | |
|---|---|---|---|
| CA2338414A1 | Canada | A1 | |
| CA2467974A1 | Canada | A1 | |
| CA2467998A1 | Canada | A1 | |
| WO0008909A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU5481899A | Australia | A | |
| WO0008909A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1077398A1 | European Patent Office (EPO) | A1 | |
| EP1085443A2 | European Patent Office (EPO) | A2 | |
| CN1289100A | China | A | |
| US6226618B1 | United States of America | B1 | |
| EP1104555A2 | European Patent Office (EPO) | A2 | |
| JP2001160003A | Japan | A | |
| KR20010050111A | Republic of Korea | A | |
| KR20010050381A | Republic of Korea | A | |
| US6263313B1 | United States of America | B1 | |
| TW454132B | Taiwan Province of China | B | |
| CN1320232A | China | A | |
| IL137880D0 | Israel | D0 | |
| US2002002468A1 | United States of America | A1 | |
| US6345256B1 | United States of America | B1 | |
| IL140935D0 | Israel | D0 | |
| US6389403B1 | United States of America | B1 | |
| US6389538B1 | United States of America | B1 | |
| US6398245B1 | United States of America | B1 | |
| US6418421B1 | United States of America | B1 | |
| JP2002522995A | Japan | A | |
| US2002107803A1 | United States of America | A1 | |
| KR100374524B1 | Republic of Korea | B1 | |
| WO03019553A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW530267B | Taiwan Province of China | B | |
| US6574609B1 | United States of America | B1 | |
| US2003105718A1 | United States of America | A1 | |
| US6587837B1 | United States of America | B1 | |
| AU763380B2 | Australia | B2 | |
| US6611812B2 | United States of America | B2 | |
| TW200304126A | Taiwan Province of China | A | |
| EP1421583A1 | European Patent Office (EPO) | A1 | |
| KR100444695B1 | Republic of Korea | B1 | |
| CN1163805C | China | C | |
| TWI222057B | Taiwan Province of China | B | |
| EP1085443A3 | European Patent Office (EPO) | A3 | |
| JP2005501322A | Japan | A | |
| US6859791B1 | United States of America | B1 | |
| JP2005122708AThis record | Japan | A | |
| JP2005122709A | Japan | A | |
| JP2005122710A | Japan | A | |
| JP2005124165A | Japan | A | |
| EP1421583B1 | European Patent Office (EPO) | B1 | |
| AT295989T | Austria | T | |
| ATE295989T1 | Austria | T1 | |
| DE60204227D1 | Germany | D1 | |
| US6959288B1 | United States of America | B1 | |
| US2005251491A1 | United States of America | A1 | |
| CN1703749A | China | A | |
| IL140935A | Israel | A | |
| US6983371B1 | United States of America | B1 | |
| DE60204227T2 | Germany | T2 | |
| US2006085343A1 | United States of America | A1 | |
| CA2467998C | Canada | C | |
| US2006089912A1 | United States of America | A1 | |
| US2006095792A1 | United States of America | A1 | |
| CA2338414C | Canada | C | |
| TWI255443B | Taiwan Province of China | B | |
| US7110984B1 | United States of America | B1 | |
| EP1077398B1 | European Patent Office (EPO) | B1 | |
| AT340379T | Austria | T | |
| ATE340379T1 | Austria | T1 | |
| DE60030814D1 | Germany | D1 | |
| SG130009A1 | Singapore | A1 | |
| US7206748B1 | United States of America | B1 | |
| US7228437B2 | United States of America | B2 | |
| US7269564B1 | United States of America | B1 | |
| DE60030814T2 | Germany | T2 | |
| CN100345157C | China | C | |
| US7346580B2 | United States of America | B2 | |
| JP4086825B2 | Japan | B2 | |
| US7383228B2 | United States of America | B2 | |
| JP4113865B2 | Japan | B2 | |
| CN100403325C | China | C | |
| US2008172747A1 | United States of America | A1 | |
| EP1085443B1 | European Patent Office (EPO) | B1 | |
| AT406622T | Austria | T | |
| ATE406622T1 | Austria | T1 | |
| DE60040041D1 | Germany | D1 | |
| JP4208803B2 | Japan | B2 | |
| JP4209592B2 | Japan | B2 | |
| US7487128B2 | United States of America | B2 | |
| US7590866B2 | United States of America | B2 | |
| JP4347508B2 | Japan | B2 | |
| US2010008500A1 | United States of America | A1 | |
| CA2467974C | Canada | C | |
| JP4549673B2 | Japan | B2 | |
| JP4565940B2 | Japan | B2 | |
| US7962413B2 | United States of America | B2 | |
| US7962750B1 | United States of America | B1 | |
| EP2400417A2 | European Patent Office (EPO) | A2 | |
| EP2402878A1 | European Patent Office (EPO) | A1 | |
| EP2400417A3 | European Patent Office (EPO) | A3 | |
| US8180708B2 | United States of America | B2 | |
| EP2400417B1 | European Patent Office (EPO) | B1 |
44 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: R3D02RD02 | RD02 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification for declining of transfer of rightsJAPANESE INTERMEDIATE CODE: R360R360 | R360 | |
| Transfer withdrawnWithdrawnJAPANESE INTERMEDIATE CODE: R371R371 | R371 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification for declining of transfer of rightsJAPANESE INTERMEDIATE CODE: R360R360 | R360 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Notification before disposition of declining of applicationJAPANESE INTERMEDIATE CODE: R155R155 | R155 | |
| Notification before disposition of declining of applicationJAPANESE INTERMEDIATE CODE: R155R155 | R155 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A821A521 | A521 | |
| Notification of resignation of power of sub attorneyJAPANESE INTERMEDIATE CODE: A7434RD14 | RD14 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A821A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A821A521 | A521 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 2005122708
- Publication, DOCDB
- 2005122708
- Publication, EPODOC
- JP2005122708
- Application
- 264471
- Application, DOCDB
- 2004264471
- Application, EPODOC
- JP20040264471
Titles2
- Japanese
- エンドユーザの電子コンテンツ使用を追跡するシステム
- English
- A system that tracks end-user electronic content usage
Classification
- CPC, 19
- G06F21/10
- G06F2221/2135
- G06Q20/3674
- G06Q20/382
- G06Q20/3829
- G06Q30/0617
- G06Q30/0623
- G06Q30/0633
- H04L9/0822
- H04L9/0825
- H04L63/0428
- H04L2463/101
- H04L2463/102
- H04L69/329
- H04L2209/603
- H04W4/029
- H04W4/02
- H04L67/52
- G06F21/16
- IPC, 22
- G06F1 00
- G06F21 10
- G06F21 16
- G06F21 60
- G06F21 62
- G06F21 64
- G06Q20 36
- G06Q20 38
- G06Q30 06
- G09C1 00
- G10K15 02
- H03M7 30
- H04L9 08
- H04L9 10
- H04L29 06
- H04L29 08
- H04N7 167
- H04N7 173
- H04N21 2347
- H04N21 418
- H04W4 02
- H04W4 029