Contents utilizing information providing apparatus and contents utilizing information appreciation apparatus
Abstract
Problem to be solved.To improve processing efficiency when inputting / outputting encrypted data to be kept secret between a recording device and a host device. A certificate C of a license data transmission destination (storage device 200 at the time of recording, a playback device 300 at the time of reading) and a license data transmission destination (storage device 200 at the time of recording, playback device 300 at the time of reading). After verifying [KPdx] (hereinafter, x is the destination of the license data and y is the source of the license data), the source certificate C [KPdy] of the license data and the challenge information E (KPdx, Kcy // C [KPdx, Kcy // C] By sending from the source to the destination as KPdy]) and verifying this source certificate C [KPdy] at the destination, if the source device is verified as valid, the license data will be provided. If the source device is verified to be invalid, the license data will be refused. [Selection diagram] Fig. 8

Term
Term ended
Projected expiry passed 21 July 2024, 2.2 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
5 claims: 2 independent, 3 dependent
- 1暗号化コンテンツデータおよび前記暗号化コンテンツデータを復号するためのコンテンツ利用情報をコンテンツ利用情報享受装置に記録するコンテンツ利用情報提供装置であって、 指示を入力するための操作部と、 前記コンテンツ利用情報享受装置との間でデータの授受を制御するインタフェースと、 前記暗号化コンテンツデータおよび前記コンテンツ利用情報を記憶する記憶部と、 自身の認証データを保持する認証データ保持部と、 公開認証鍵によってデータを認証する認証部と、 前記コンテンツ利用情報享受装置との通信を特定するための第1の対称鍵を生成する対称鍵生成部と、 前記コンテンツ利用情報享受装置に設定された第1の公開鍵によって、データを暗号化する第1の暗号部と、 前記対称鍵生成部により生成された第1対称鍵によってデータを復号する復号部と、 前記コンテンツ利用情報享受装置に設定された第2の公開鍵によってデータを暗号化する第2の暗号部と、 前記コンテンツ利用情報享受装置で生成された第2の対称鍵によってデータを暗号化する第3の暗号部と、 制御部とを備え、 前記制御部は、 前記操作部を介して入力された前記コンテンツ利用情報の出力要求に応じて、 前記第1の公開鍵と前記コンテンツ利用情報享受装置の証明書とを前記公開認証鍵によって暗号化して成る認証データを、前記インタフェースを介して前記コンテンツ利用情報享受装置から受け取り、その受け取った認証データを前記認証部に与え、前記認証部において前記公開認証鍵によって復号された前記第1の公開鍵および前記証明書に基づいて前記コンテンツ利用情報享受装置が正規か否かを判定し、前記コンテンツ利用情報享受装置が正規であるとき、前記第1の対称鍵を生成するように前記対称鍵生成部を制御し、前記第1の暗号部において前記第1の公開鍵によって暗号化された、前記第1の対称鍵と前記自身の認証データとを、前記インタフェースを介して前記コンテンツ利用情報享受装置へ送信し、 前記第1の対称鍵によって暗号化された前記第2の対称鍵および前記第2の公開鍵を前記インタフェースを介して前記コンテンツ利用情報享受装置から受け取り、その受け取った前記暗号化された前記第2の対称鍵および前記第2の公開鍵を前記復号部に与え、 前記記憶部から前記コンテンツ利用情報を読み出して前記第2の暗号部に与え、前記第2の公開鍵と前記コンテンツ利用情報享受装置において生成された第2の対称鍵とによって順次暗号化された暗号化コンテンツ利用情報を、前記インタフェースを介して前記コンテンツ利用情報享受装置へ送信し、 前記認証部は、前記認証データを前記公開認証鍵によって復号し、その復号した第1の公開鍵を前記第1の暗号部に与え、前記復号した証明書を前記制御部に与え、 前記第1の暗号部は、前記第1の対称鍵と前記認証データ保持部から読み出した前記自身の認証データとを連結し、これを前記第1の公開鍵によって暗号化して前記制御部に与え、 前記復号部は、前記暗号化された前記第2の対称鍵および前記第2の公開鍵を前記第1の対称鍵によって復号し、その復号した前記第2の公開鍵を前記第2の暗号部に与え、前記復号した前記第2の対称鍵を前記第3の暗号部に与え、 前記第2の暗号部は、前記コンテンツ利用情報を前記第2の公開鍵によって暗号化して前記第3の暗号部に与え、 前記第3の暗号部は、前記第2の公開鍵によって暗号化された前記コンテンツ利用情報を前記第2の対称鍵によってさらに暗号化して前記制御部に与える、コンテンツ利用情報提供装置。
- 2前記記憶部は、 前記暗号化コンテンツデータを格納する第1の格納部と、 前記コンテンツ利用情報を格納する第2の格納部とを含み、 前記第2の格納部は、耐タンパ構造によって構成される、請求項1に記載のコンテンツ利用情報提供装置。
- 3暗号化コンテンツデータおよび前記暗号化コンテンツデータを復号および再生するためのコンテンツ利用情報を記録したコンテンツ利用情報提供装置から前記暗号化コンテンツデータおよび前記コンテンツ利用情報を取得して前記暗号化コンテンツデータを再生するコンテンツ利用情報享受装置であって、 指示を入力するための操作部と、 前記コンテンツ利用情報提供装置との間でデータの授受を制御するインタフェースと、 自身の認証データを保持する認証データ保持部と、 前記暗号化コンテンツデータを前記コンテンツ利用情報に含まれるコンテンツ鍵によって復号してコンテンツデータを再生するコンテンツ再生回路と、 前記認証データに含まれ、かつ、前記コンテンツ再生回路に設定された第1の公開鍵によって暗号化されたデータを復号するための第1の秘密鍵を保持する第1秘密鍵保持部と、 前記コンテンツ再生回路に設定された第2の公開鍵を保持する第2公開鍵保持部と、 前記第2の公開鍵によって暗号化されたデータを復号するための第2の秘密鍵を保持する第2秘密鍵保持部と、 前記第1の公開鍵によって暗号化されたデータを前記第1の秘密鍵で復号する第1の復号部と、 公開認証鍵によってデータを認証する認証部と、 前記コンテンツ利用情報提供装置で生成された第1の対称鍵によって、データを暗号化する暗号部と、 前記コンテンツ利用情報提供装置との通信を特定するための第2の対称鍵を生成する対称鍵生成部と、 前記第2対称鍵で暗号化されたデータを復号する第2の復号部と、 前記第2の公開鍵によって暗号かされたデータを前記第2の秘密鍵によってデータを復号する第3の復号部と、 制御部とを備え、 前記制御部は、前記操作部を介して入力された前記暗号化コンテンツデータの再生要求に応じて、 前記認証データを前記インタフェースを介して前記コンテンツ利用情報提供装置へ送信し、前記コンテンツ利用情報提供装置において前記認証データが認証されると、前記第1公開鍵によって暗号化された前記第1の対称鍵と前記コンテンツ利用情報提供装置の証明書を前記公開認証鍵によって暗号化して成る認証データとを前記インタフェースから受け取り、その受け取った前記暗号化された第1の対称鍵と前記コンテンツ利用情報提供装置の認証データを前記第1の復号部に与え、 前記認証部において前記公開認証鍵によって復号された前記証明書に基づいて前記コンテンツ利用情報提供装置が正規か否かを判定し、前記コンテンツ利用情報提供装置が正規であるとき、前記第2の対称鍵を生成するように前記対称鍵生成部を制御し、 前記暗号部において前記第1の対称鍵によって暗号化された前記第2の対称鍵と前記第2の公開鍵とを前記インタフェースを介して前記コンテンツ利用情報提供装置へ送信し、 前記第2の公開鍵および前記第2の対称鍵によって順次暗号化された暗号化コンテンツ利用情報を、前記インタフェースを介して受信し、その受信した暗号化コンテンツ利用情報を前記第2の公開鍵および前記対称鍵によって順次暗号化された暗号化コンテンツ利用情報を、前記インタフェースを介して受信し、その受信した暗号化コンテンツ利用情報を前記第2の復号部に与え、 前記第1の復号部は、前記第1の公開鍵によって暗号化された前記第1の対称鍵と前記コンテンツ利用情報提供装置の認証データとを前記第1の秘密鍵によって復号して前記第1の対称鍵を前記第1の暗号部に与え、前記コンテンツ利用情報提供装置の認証データを前記認証部に与え、 前記第1暗号部は、前記第2公開鍵保持部からの前記第2公開鍵と前記対称鍵生成部からの前記第2の対称鍵とを前記第1の対称鍵によって暗号化して前記制御部へ出力し、 前記認証部は、前記認証データを前記公開認証鍵によって復号し、その復号した証明書を前記制御部に与え、 前記第2の復号部は、前記対称鍵によって復号されたデータを前記第3の復号部に与え、 前記第3の復号部は、前記第2の秘密鍵によって復号したコンテンツ利用情報に含まれる前記コンテンツ復号鍵を前記コンテンツ再生回路に与える、コンテンツ利用情報享受装置。
- 4前記制御部は、前記認証部において前記公開認証鍵によって復号された前記第1の公開鍵および前記証明書に基づいて前記コンテンツ利用情報提供装置が正規か否かを判定し、前記コンテンツ利用情報提供装置が正規でないとき、前記再生要求に対する本処理を終了する、請求項3に記載のコンテンツ利用情報享受装置。
- 5前記コンテンツ再生回路は、前記暗号化コンテンツデータを前記コンテンツ利用情報鍵によって復号する第4の復号部と、 前記第4の復号部によって復号されたコンテンツデータを再生する再生部とを含む、請求項3または請求項4に記載のコンテンツ利用情報享受装置。
Independent claims5
170 paragraphs, as filed
The present invention relates to a data input / output technique, and more particularly to a technique for encrypting and inputting / outputting data to be kept secret between a storage device and a host device.
As a content data distribution system with enhanced confidentiality of license data, for example, in Patent Document 1, a device that handles license data in an unencrypted state is used as a server device, a memory card (storage device), and a decoder (utilized device). Three devices are classified, and for sending and receiving license data between devices (server device and storage device, storage device and used device), an encrypted communication path is constructed between the two devices that send and receive license data, and the encryption is performed. The recording device, storage device, and utilization device are provided with a TRM (Tamper-Resistant-Module) that can handle encrypted license data while performing via a communication path.
In the construction of the encrypted communication path, the device that first enjoys the license data (called the license enjoying device) transmits the certificate including the public key to the device that provides the license data (called the license providing device). Then, when the license providing device verifies this certificate, and as a result of the verification, the certificate from the licensed device is a legitimate certificate and is not invalidated by the certificate revocation list. The public key included in the certificate is used to exchange keys between devices. Then, the license providing device transmits the license data encrypted with the key sent from the license enjoying device in the key exchange to the license enjoying device.
The TRM is a circuit module whose confidentiality is physically protected, and is configured to restrict the exchange of license data with other devices other than via an encrypted communication path.
At the time of acquiring the license data, the memory card is attached to the terminal device capable of communicating with the server device, and the license data is received from the server device via the terminal device. When using the content, the memory card is attached to a terminal device having a built-in decoder, and license data is transmitted to the decoder via the terminal device.
As described above, in the content distribution service, the copyright of the content is thoroughly protected by encrypting the content data and concealing the license data. By thoroughly protecting the content copyright in this way, the content to be distributed can be added to the lineup with peace of mind, and as a result, the needs of users who receive the distribution service can be met more broadly. Will be.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2004-133454</text></patcit>
<p> As described above, in the conventional content distribution system, it is not necessary to pay attention to the safety of the server device which is the license providing device. Even if fake license data is recorded in the storage device that is the license enjoyer by a fake server device impersonating the server device, this action does not mean the leakage of the content, that is, the content right holder. Did not threaten his rights. Even in the case of reproduction, even if fake license data is supplied to the user device which is the license enjoying device by spoofing the storage device which is the license providing device, the legitimate encrypted content data is not reproduced. In other words, spoofing to the license providing device did not lose the rights of the content right holder due to the leakage of the content.</p><p> However, when considering a recorder that digitally records a video signal or video data as a licensing device using this copyright protection function, the recorder whose safety is impaired (it was originally legitimate, but for some reason its safety). It is necessary to consider a recorder whose sex has been impaired) or a fake recorder. Generally, the recorder receives the recorded content as a broadcast or line input (RCF terminal, S terminal, IEEE1394, etc.). These contents need to be recorded in the storage device after observing the protection requirements predetermined for each input method and the recording conditions multiplexed on the signal itself. A recorder that does not meet these conditions should be considered as a device that cannot protect the rights of the content right holder. If such a licensing device cannot stop providing the license, the storage device, which is the licensing device, should refuse to enter such license data. Similarly, the device used should refuse to provide license data from a secure storage device or a fake storage device.</p><p> The present invention has been made in view of such a situation, and an object of the present invention is to authenticate each other when inputting / outputting data to be kept secret between a storage device and a host device in an encrypted manner to secure the contents. Moreover, it is intended to provide a recording device and a host device capable of accurately inputting and outputting.</p><p> That is, license data can be safely and accurately input / output between the license providing device (recorder or storage device) and the license receiving device (storage device or used device), and the license receiving device is safe. Provides the ability to refuse to record license data from a compromised or fake license provider.</p>
<p> In view of the above problems, the present invention has the following features.</p><p> The invention of claim 1 is a content usage information providing device that records encrypted content data and content usage information for decrypting the encrypted content data in a content usage information enjoying device, and is an operation for inputting an instruction. An interface for controlling the exchange of data between the unit and the content usage information enjoying device, a storage unit for storing the encrypted content data and the content usage information, and an authentication data holding unit for holding its own authentication data. , An authentication unit that authenticates data with a public authentication key, a symmetric key generation unit that generates a first symmetric key for specifying communication with the content usage information enjoying device, and the content usage information enjoying device. The first encryption unit that encrypts data with the first public key, the decryption unit that decrypts data with the first symmetric key generated by the symmetric key generation unit, and the content usage information enjoyment device. Control: a second encryption unit that encrypts data with the set second public key, and a third encryption unit that encrypts data with the second symmetric key generated by the content usage information enjoying device. The control unit discloses the first public key and the certificate of the content usage information enjoying device in response to an output request for the content usage information input via the operation unit. The authentication data encrypted by the authentication key is received from the content usage information enjoying device via the interface, the received authentication data is given to the authentication unit, and the authentication unit is decrypted by the public authentication key. It is determined whether or not the content usage information enjoying device is legitimate based on the first public key and the certificate, and when the content usage information enjoying device is legitimate, the first symmetric key is generated. The content of the first symmetric key and its own authentication data, which controls the symmetric key generation unit and is encrypted by the first public key in the first encryption unit, via the interface. The second symmetric key transmitted to the usage information enjoying device and encrypted by the first symmetric key and the saidThe second public key is received from the content usage information enjoying device via the interface, and the received encrypted second symmetric key and the second public key are given to the decryption unit, and the storage is performed. Encrypted content that is read from the unit and given to the second encryption unit, and is sequentially encrypted by the second public key and the second symmetric key generated by the content usage information enjoying device. The usage information is transmitted to the content usage information enjoying device via the interface, the authentication unit decrypts the authentication data with the public authentication key, and the decrypted first public key is encrypted with the first encryption. The decrypted certificate is given to the control unit, and the first encryption unit concatenates the first symmetric key and its own authentication data read from the authentication data holding unit. Is encrypted with the first public key and given to the control unit, and the decryption unit decrypts the encrypted second symmetric key and the second public key with the first symmetric key. , The decrypted second public key is given to the second encryption unit, the decrypted second symmetric key is given to the third encryption unit, and the second encryption unit uses the content. The information is encrypted by the second public key and given to the third encryption unit, and the third encryption unit transfers the content usage information encrypted by the second public key to the second symmetry. It is characterized in that it is further encrypted by a key and given to the control unit.Then, the decrypted first public key is given to the first encryption unit, the decrypted certificate is given to the control unit, and the first encryption unit gives the first symmetric key and the authentication data. The own authentication data read from the holding unit is concatenated, encrypted by the first public key and given to the control unit, and the decryption unit uses the encrypted second symmetric key and the encrypted second symmetric key. The second public key is decrypted by the first symmetric key, the decrypted second public key is given to the second encryption unit, and the decrypted second symmetric key is given to the third. It is given to the encryption unit, the second encryption unit encrypts the content usage information with the second public key and gives it to the third encryption unit, and the third encryption unit is the second disclosure. The content usage information encrypted by the key is further encrypted by the second symmetric key and given to the control unit.Then, the decrypted first public key is given to the first encryption unit, the decrypted certificate is given to the control unit, and the first encryption unit gives the first symmetric key and the authentication data. The own authentication data read from the holding unit is concatenated, encrypted by the first public key and given to the control unit, and the decryption unit uses the encrypted second symmetric key and the encrypted second symmetric key. The second public key is decrypted by the first symmetric key, the decrypted second public key is given to the second encryption unit, and the decrypted second symmetric key is given to the third. It is given to the encryption unit, the second encryption unit encrypts the content usage information with the second public key and gives it to the third encryption unit, and the third encryption unit is the second disclosure. The content usage information encrypted by the key is further encrypted by the second symmetric key and given to the control unit.</p><p> The invention of claim 2 is the content usage information providing device according to claim 1, wherein the storage unit stores a first storage unit for storing the encrypted content data and a first storage unit for storing the content usage information. The second storage unit includes two storage units, and the second storage unit is characterized by having a tamper-resistant structure.</p><p> The invention of claim 3 acquires the encrypted content data and the content usage information from a content usage information providing device that records the encrypted content data and the content usage information for decrypting and reproducing the encrypted content data. A content usage information enjoying device that reproduces the encrypted content data, an interface that controls data transfer between an operation unit for inputting an instruction, and the content usage information providing device, and own authentication data. The authentication data holding unit that holds the above, the content reproduction circuit that decrypts the encrypted content data by the content key included in the content usage information and reproduces the content data, and the content reproduction that is included in the authentication data and that is included in the authentication data. A first private key holder that holds a first private key for decrypting data encrypted by a first public key set in the circuit, and a second public key set in the content reproduction circuit. A second public key holder that holds the second private key, a second private key holder that holds the second private key for decrypting data encrypted by the second public key, and the first public key. A first decryption unit that decrypts the data encrypted by the first private key, an authentication unit that authenticates the data with the public authentication key, and a first symmetric key generated by the content usage information providing device. A cipher unit that encrypts data, a symmetric key generator that generates a second symmetric key for specifying communication with the content usage information providing device, and data encrypted with the second symmetric key. The control unit includes a second decryption unit that decrypts the data, a third decryption unit that decrypts the data encrypted by the second public key with the second private key, and a control unit. In response to the playback request of the encrypted content data input via the operation unit, transmits the authentication data to the content usage information providing device via the interface, and the content usage information providing device performs the above. When the authentication data is authenticated, the first symmetric key encrypted by the first public key and the content usage information are used.The authentication data obtained by encrypting the certificate of the information providing device with the public authentication key is received from the interface, and the received encrypted first symmetric key and the authentication data of the content usage information providing device are received. It is given to the first decryption unit, and the authentication unit determines whether or not the content usage information providing device is legitimate based on the certificate decrypted by the public authentication key, and the content usage information providing device is legitimate. At one time, the symmetric key generator is controlled so as to generate the second symmetric key, and the second symmetric key and the second disclosure encrypted by the first symmetric key in the encryption unit are used. The key is transmitted to the content usage information providing device via the interface, and the encrypted content usage information sequentially encrypted by the second public key and the second symmetric key is received via the interface. Then, the received encrypted content usage information is sequentially encrypted by the second public key and the symmetric key via the interface, and the received encrypted content usage information is received. Is given to the second decryption unit, and the first decryption unit transfers the first symmetric key encrypted by the first public key and the authentication data of the content usage information providing device to the first. The first symmetric key is given to the first encryption unit by decryption with the private key of the above, and the authentication data of the content usage information providing device is given to the authentication unit. The second public key from the key holding unit and the second symmetric key from the symmetric key generation unit are encrypted by the first symmetric key and output to the control unit, and the authentication unit performs the authentication. The data is decrypted by the public authentication key, the decrypted certificate is given to the control unit, and the second decryption unit gives the data decrypted by the symmetric key to the third decryption unit, and the second decryption unit gives the decrypted certificate to the third decryption unit. The decryption unit of 3 is characterized in that the content decryption key included in the content usage information decrypted by the second private key is given to the content reproduction circuit.Therefore, the encrypted authentication data is received from the interface, and the received encrypted first symmetric key and the authentication data of the content usage information providing device are given to the first decryption unit, and the authentication unit is used. Determines whether the content usage information providing device is legitimate based on the certificate decrypted by the public authentication key, and when the content usage information providing device is legitimate, the second symmetric key is generated. The symmetric key generation unit is controlled so as to perform the above-mentioned content utilization of the second symmetric key and the second public key encrypted by the first symmetric key in the encryption unit via the interface. The encrypted content usage information transmitted to the information providing device and sequentially encrypted by the second public key and the second symmetric key is received via the interface, and the received encrypted content usage information is received. The encrypted content usage information sequentially encrypted by the second public key and the symmetric key is received via the interface, and the received encrypted content usage information is given to the second decryption unit. The first decryption unit decrypts the first symmetric key encrypted by the first public key and the authentication data of the content usage information providing device by the first private key, and the first decryption unit. A symmetric key is given to the first encryption unit, authentication data of the content usage information providing device is given to the authentication unit, and the first encryption unit is the second public key from the second public key holding unit. The second symmetric key from the symmetric key generation unit is encrypted by the first symmetric key and output to the control unit, and the authentication unit decrypts the authentication data by the public authentication key and outputs the encryption data to the control unit. The decrypted certificate is given to the control unit, the second decryption unit gives the data decrypted by the symmetric key to the third decryption unit, and the third decryption unit gives the second secret. The content decryption key included in the content usage information decrypted by the key is given to the content reproduction circuit.Therefore, the encrypted authentication data is received from the interface, and the received encrypted first symmetric key and the authentication data of the content usage information providing device are given to the first decryption unit, and the authentication unit is used. Determines whether the content usage information providing device is legitimate based on the certificate decrypted by the public authentication key, and when the content usage information providing device is legitimate, the second symmetric key is generated. The symmetric key generation unit is controlled so as to perform the above-mentioned content utilization of the second symmetric key and the second public key encrypted by the first symmetric key in the encryption unit via the interface. The encrypted content usage information transmitted to the information providing device and sequentially encrypted by the second public key and the second symmetric key is received via the interface, and the received encrypted content usage information is received. The encrypted content usage information sequentially encrypted by the second public key and the symmetric key is received via the interface, and the received encrypted content usage information is given to the second decryption unit. The first decryption unit decrypts the first symmetric key encrypted by the first public key and the authentication data of the content usage information providing device by the first private key, and the first decryption unit. The symmetric key is given to the first encryption unit, the authentication data of the content usage information providing device is given to the authentication unit, and the first encryption unit is the second public key from the second public key holding unit. The second symmetric key from the symmetric key generation unit is encrypted by the first symmetric key and output to the control unit, and the authentication unit decrypts the authentication data by the public authentication key and outputs the encryption data to the control unit. The decrypted certificate is given to the control unit, the second decryption unit gives the data decrypted by the symmetric key to the third decryption unit, and the third decryption unit gives the second secret. The content decryption key included in the content usage information decrypted by the key is given to the content reproduction circuit.The encrypted first symmetric key and the authentication data of the content usage information providing device are given to the first decryption unit, and the authentication unit is based on the certificate decrypted by the public authentication key. It is determined whether or not the content usage information providing device is legitimate, and when the content usage information providing device is legitimate, the symmetric key generator is controlled so as to generate the second symmetric key, and the encryption is performed. In the unit, the second symmetric key encrypted by the first symmetric key and the second public key are transmitted to the content usage information providing device via the interface, and the second public key and the second public key are transmitted. The encrypted content usage information sequentially encrypted by the second symmetric key is received via the interface, and the received encrypted content usage information is sequentially encrypted by the second public key and the symmetric key. The encrypted content usage information is received via the interface, and the received encrypted content usage information is given to the second decryption unit, and the first decryption unit uses the first public key. The encrypted first symmetric key and the authentication data of the content usage information providing device are decrypted by the first private key, and the first symmetric key is given to the first encryption unit to provide the content. The authentication data of the usage information providing device is given to the authentication unit, and the first encryption unit includes the second public key from the second public key holding unit and the second symmetric key from the symmetric key generation unit. Is encrypted with the first symmetric key and output to the control unit, the authentication unit decrypts the authentication data with the public authentication key, gives the decrypted certificate to the control unit, and gives the decrypted certificate to the control unit. The decryption unit of the above gives the data decoded by the symmetric key to the third decoding unit, and the third decoding unit is the content decoding key included in the content usage information decoded by the second private key. Is given to the content reproduction circuit.The encrypted first symmetric key and the authentication data of the content usage information providing device are given to the first decryption unit, and the authentication unit is based on the certificate decrypted by the public authentication key. It is determined whether or not the content usage information providing device is legitimate, and when the content usage information providing device is legitimate, the symmetric key generator is controlled so as to generate the second symmetric key, and the encryption is performed. In the unit, the second symmetric key encrypted by the first symmetric key and the second public key are transmitted to the content usage information providing device via the interface, and the second public key and the second public key are transmitted. The encrypted content usage information sequentially encrypted by the second symmetric key is received via the interface, and the received encrypted content usage information is sequentially encrypted by the second public key and the symmetric key. The encrypted content usage information is received via the interface, and the received encrypted content usage information is given to the second decryption unit, and the first decryption unit uses the first public key. The encrypted first symmetric key and the authentication data of the content usage information providing device are decrypted by the first private key, and the first symmetric key is given to the first encryption unit to provide the content. The authentication data of the usage information providing device is given to the authentication unit, and the first encryption unit includes the second public key from the second public key holding unit and the second symmetric key from the symmetric key generation unit. Is encrypted with the first symmetric key and output to the control unit, the authentication unit decrypts the authentication data with the public authentication key, gives the decrypted certificate to the control unit, and gives the decrypted certificate to the control unit. The decryption unit of the above gives the data decoded by the symmetric key to the third decoding unit, and the third decoding unit is the content decoding key included in the content usage information decoded by the second private key. Is given to the content reproduction circuit.Based on the decrypted certificate, it is determined whether or not the content usage information providing device is legitimate, and when the content usage information providing device is legitimate, the symmetry is generated so as to generate the second symmetric key. The key generation unit is controlled, and the second symmetric key and the second public key encrypted by the first symmetric key in the encryption unit are transmitted to the content usage information providing device via the interface. Then, the encrypted content usage information sequentially encrypted by the second public key and the second symmetric key is received via the interface, and the received encrypted content usage information is released to the second publication. The encrypted content usage information sequentially encrypted by the key and the symmetric key is received via the interface, and the received encrypted content usage information is given to the second decryption unit, and the first decryption unit is used. Decrypts the first symmetric key encrypted by the first public key and the authentication data of the content usage information providing device with the first private key, and uses the first symmetric key to obtain the first symmetric key. It is given to the encryption unit 1, and the authentication data of the content usage information providing device is given to the authentication unit, and the first encryption unit is the second public key from the second public key holding unit and the symmetric key generation unit. The second symmetric key from the above is encrypted by the first symmetric key and output to the control unit, and the authentication unit decrypts the authentication data with the public authentication key and obtains the decrypted certificate. The content given to the control unit, the second decoding unit gives the data decrypted by the symmetric key to the third decoding unit, and the third decoding unit is the content decoded by the second private key. It is characterized in that the content decryption key included in the usage information is given to the content reproduction circuit.Based on the decrypted certificate, it is determined whether or not the content usage information providing device is legitimate, and when the content usage information providing device is legitimate, the symmetry is generated so as to generate the second symmetric key. The key generation unit is controlled, and the second symmetric key and the second public key encrypted by the first symmetric key in the encryption unit are transmitted to the content usage information providing device via the interface. Then, the encrypted content usage information sequentially encrypted by the second public key and the second symmetric key is received via the interface, and the received encrypted content usage information is released to the second publication. The encrypted content usage information sequentially encrypted by the key and the symmetric key is received via the interface, and the received encrypted content usage information is given to the second decryption unit, and the first decryption unit is used. Decrypts the first symmetric key encrypted by the first public key and the authentication data of the content usage information providing device with the first private key, and uses the first symmetric key to obtain the first symmetric key. It is given to the encryption unit 1, and the authentication data of the content usage information providing device is given to the authentication unit, and the first encryption unit is the second public key from the second public key holding unit and the symmetric key generation unit. The second symmetric key from the above is encrypted by the first symmetric key and output to the control unit, and the authentication unit decrypts the authentication data with the public authentication key and obtains the decrypted certificate. The content given to the control unit, the second decoding unit gives the data decrypted by the symmetric key to the third decoding unit, and the third decoding unit is the content decoded by the second private key. It is characterized in that the content decryption key included in the usage information is given to the content reproduction circuit.The encrypted content usage information transmitted to the content usage information providing device via the interface and sequentially encrypted by the second public key and the second symmetric key is received via the interface and received. The encrypted content usage information that has been sequentially encrypted by the second public key and the symmetric key is received via the interface, and the received encrypted content usage information is received by the second. The first decryption unit gives the first symmetric key encrypted by the first public key and the authentication data of the content usage information providing device to the decryption unit of the first public key. Decrypt and give the first symmetric key to the first encryption unit, give the authentication data of the content usage information providing device to the authentication unit, and the first encryption unit is from the second public key holding unit. The second public key and the second symmetric key from the symmetric key generation unit are encrypted by the first symmetric key and output to the control unit, and the authentication unit publishes the authentication data. It is decrypted by the authentication key, the decrypted certificate is given to the control unit, the second decryption unit gives the data decrypted by the symmetric key to the third decryption unit, and the third decryption unit Is characterized in that the content decryption key included in the content usage information decrypted by the second private key is given to the content reproduction circuit.The encrypted content usage information transmitted to the content usage information providing device via the interface and sequentially encrypted by the second public key and the second symmetric key is received via the interface and received. The encrypted content usage information that has been sequentially encrypted by the second public key and the symmetric key is received via the interface, and the received encrypted content usage information is received by the second. The first decryption unit gives the first symmetric key encrypted by the first public key and the authentication data of the content usage information providing device to the decryption unit of the first public key. Decrypt and give the first symmetric key to the first encryption unit, give the authentication data of the content usage information providing device to the authentication unit, and the first encryption unit is from the second public key holding unit. The second public key and the second symmetric key from the symmetric key generation unit are encrypted by the first symmetric key and output to the control unit, and the authentication unit publishes the authentication data. It is decrypted by the authentication key, the decrypted certificate is given to the control unit, the second decryption unit gives the data decrypted by the symmetric key to the third decryption unit, and the third decryption unit. Is characterized in that the content decryption key included in the content usage information decrypted by the second private key is given to the content reproduction circuit.It is given to the first encryption unit, the authentication data of the content usage information providing device is given to the authentication unit, and the first encryption unit generates the second public key and the symmetric key from the second public key holding unit. The second symmetric key from the unit is encrypted by the first symmetric key and output to the control unit, and the authentication unit decrypts the authentication data with the public authentication key and the decrypted certificate. Was given to the control unit, the second decoding unit provided the data decoded by the symmetric key to the third decoding unit, and the third decoding unit decoded the data decrypted by the second private key. It is characterized in that the content decryption key included in the content usage information is given to the content reproduction circuit.It is given to the first encryption unit, the authentication data of the content usage information providing device is given to the authentication unit, and the first encryption unit generates the second public key and the symmetric key from the second public key holding unit. The second symmetric key from the unit is encrypted by the first symmetric key and output to the control unit, and the authentication unit decrypts the authentication data with the public authentication key and the decrypted certificate. Was given to the control unit, the second decoding unit provided the data decoded by the symmetric key to the third decoding unit, and the third decoding unit decoded the data decrypted by the second private key. It is characterized in that the content decryption key included in the content usage information is given to the content reproduction circuit.</p><p> The invention of claim 4 is the content usage information enjoying device according to claim 3, wherein the control unit uses the first public key and the certificate decrypted by the public authentication key in the authentication unit. Based on this, it is determined whether or not the content usage information providing device is legitimate, and when the content usage information providing device is not legitimate, the present process for the reproduction request is terminated.</p><p> The invention of claim 5 is the content usage information enjoying device according to claim 3 or 4, wherein the content reproduction circuit decrypts the encrypted content data by the content usage information key. It is characterized by including a unit and a reproduction unit that reproduces the content data decoded by the fourth decoding unit.</p><p> The features of the present invention or its technical significance will be further clarified by the description of the embodiments shown below. However, the following embodiments are merely one embodiment of the present invention, and the meanings and the like of terms of the present invention and each constituent requirement are limited to those described in the following embodiments. is not it.</p>
<p> According to the present invention, since the license data transmitting side is verified on the license data receiving side, the receiving side can prohibit the use of the defective recorder and the defective storage device, and it is possible to prevent the inflow of inappropriate contents. And it becomes possible to protect the rights of the content right holder.</p>
Embodiments of the present invention will be described below with reference to the drawings. (First Embodiment) FIG. 1 shows the overall configuration of the data management system 10 according to the first embodiment.
The data management system 10 includes a recording device 100 that controls the recording of data on the storage device 200, a playback device 300 that controls playback of the data recorded on the storage device 200, and a storage device 200 that records and holds the data.
The storage device 200 of the present embodiment includes not only a storage medium that holds data, but also a controller that controls input / output of data between a host device such as a recording device 100 or a playback device 300 and a storage medium. It is a drive-integrated storage device equipped with. In the present embodiment, a hard disk drive will be described as an example of the storage device 200.
Conventional hard disk drives are generally used by being fixedly connected to one host device, but the storage device 200 of the present embodiment is a host device such as a recording device 100 and a playback device 300. It is configured to be removable. That is, the storage device 200 of the present embodiment can be removed from the host device and carried around like a CD or DVD, and has a plurality of recording devices 100, a playback device 300, a recording / playback device capable of recording and playback, and the like. It is a storage device that can be shared between host devices.
As described above, the storage device 200 of the present embodiment is premised on being connected to a plurality of host devices, and is connected to, for example, a host device of a third party other than the owner and recorded internally. There is also the possibility that the data will be read.
When it is assumed that the storage device 200 records confidential data such as music, video, and other copyright-protected content, and confidential company and personal information, the confidential data will be leaked to the outside. In order to prevent this, it is preferable that the storage device 200 itself is provided with a configuration for appropriately protecting data and has a sufficient tamper resistance function.
From this point of view, the storage device 200 of the present embodiment includes a configuration for encrypting and exchanging the secret data when inputting / outputting the secret data to / from the host device. Further, in order to store the confidential data, a confidential data storage area different from the normal storage area is provided, and the confidential data storage area is configured so that the confidential data storage area can be accessed only through the encryption engine provided in the storage device 200. .. This cryptographic engine inputs and outputs confidential data only to host devices that have been verified to have legitimate authority.
Hereinafter, such a data protection function is also referred to as a "secure function".
With the above configuration and functions, the confidential data recorded in the storage device 200 can be appropriately protected.
In order to make the best use of the characteristics of the storage device 200 as a removable medium, it is preferable that ordinary data can be input / output even to a host device that does not support the secure function. Therefore, the storage device 200 of the present embodiment supports ATA (AT Attachment), which is a standard of ANSI (American National Standards Institute), in order to maintain compatibility with a conventional hard disk, and has the above-mentioned secure function. Is realized as an extended instruction of ATA.
Hereinafter, as an example of input / output of confidential data, a case where content data such as a video is recorded and reproduced will be described. The content data itself may be treated as confidential data, but in the present embodiment, the content data is encrypted, and the encrypted content data itself is recorded in the storage device 200 as normal data. Then, data (license data) including a key for decrypting the encrypted content (called a content key) and information on control of content playback control, license use, movement, and duplication (called usage rule). (Call) is input / output as confidential data using the above-mentioned secure function. As a result, it is possible to simplify data input / output, speed up processing, and reduce power consumption while maintaining sufficient tamper resistance.
Here, the license data includes, in addition to the content key and usage rules, a license ID for specifying the license data and the like.
Hereinafter, among the commands issued by the host devices such as the recording device 100 and the playback device 300 to the storage device 200, the extended command for the secure function is also referred to as a "secure command", and the other commands are also referred to as "normal commands". Call.
FIG. 2 shows the internal configuration of the recording device 100 according to the embodiment. In terms of hardware, this configuration can be realized by the CPU, memory, or other LSI of any computer, and in terms of software, it can be realized by a program with a recording control function loaded in the memory. Then, I draw a functional block realized by their cooperation. Therefore, it will be understood by those skilled in the art that these functional blocks can be realized in various ways by hardware only, software only, or a combination thereof.
The recording device 100 mainly includes a controller 101, a storage interface 102, a cryptographic engine 103, a cryptographic device 104, a content encoder 105, and a data bus 110 that electrically connects them.
The content encoder 105 codes the content acquired online or offline in a predetermined format. Here, the video data acquired from the broadcast wave or the like is coded in the MPEG format.
The encryption device 104 issues license data including a content key for decrypting the encrypted content, and uses the content key to encrypt the content coded by the content encoder 105.
The encrypted content is recorded on the storage device 200 via the data bus 110 and the storage interface 102. The issued license data is notified to the cryptographic engine 103 and recorded in the storage device 200 via the cryptographic engine 103.
The cryptographic engine 103 controls cryptographic communication with and from the storage device 200 in order to input license data to the storage device 200.
The storage interface 102 controls the input / output of data to / from the storage device 200. Controller over La 101 centrally controls the components of the recording apparatus 100.
FIG. 3 shows the internal configuration of the reproduction device 300 according to the embodiment. These functional blocks can also be realized in various forms by hardware only, software only, or a combination thereof.
The playback device 300 mainly includes a controller 301, a storage interface 302, a cryptographic engine 303, a decoder 304, a content decoder 305, and a data bus 310 that electrically connects them.
The storage interface 302 controls data input / output with the storage device 200.
The encryption engine 303 controls encrypted communication with the storage device 200 in order to receive the license data including the content key from the storage device 200.
The decoder 304 decrypts the encrypted content read from the storage device 200 with the content key included in the license data obtained from the storage device 200.
The content decoder 305 decodes and outputs the content decoded by the decoder 304. For example, in the case of MPEG format content, the video signal and audio signal are restored from the content, the video signal is output to a display device (not shown), and the audio signal is output to a speaker (not shown). The controller 301 comprehensively controls the components of the playback device 300.
FIG. 4 shows the internal configuration of the storage device 200 according to the embodiment. The storage device 200 mainly includes a controller 201, a storage interface 202, a cryptographic engine 203, a tamper-resistant storage unit 204, a normal data storage unit 205, and a data bus 210 that electrically connects them.
The storage interface 202 controls data input / output to and from the recording device 100 and the playback device 300.
The encryption engine 203 controls encrypted communication for inputting / outputting confidential data such as license data including a content key between the recording device 100 and the playback device 300.
The normal data storage unit 205 is a data storage area for recording encrypted contents, normal data, and the like.
The tamper-resistant storage unit 204 is a confidential data storage area for recording confidential data such as license data including a content key.
Normally, the data storage unit 205 is directly accessed (data input / output) from the outside, but the tamper-resistant storage unit 204 is configured so that it cannot be accessed (data input / output) without going through the encryption engine 203.
The controller 201 comprehensively controls the components of the storage device 200.
Here, the key used in this embodiment will be described. In this embodiment, the key is expressed as a character string starting with "K" in all uppercase letters.
If the second character "is a lowercase" c "or" s ", it represents a symmetric key (common key). If it is" c ", it is a challenge key and is a temporal generated by the source of the encrypted data. Symmetric key. In the case of "s", it is a session key, which is a temporal symmetric key generated at the destination of encrypted data.
If the second letter is an uppercase "P", it indicates the public key of public key cryptography. There is always a corresponding private key in this key, and this private key is written by excluding the uppercase "P" of the second letter from the notation of the public key.
When the character string indicating the key contains a lowercase "d", it means that the key is given for each group of devices. If the character string indicating the key contains a lowercase letter "p", it means that the key is given to each device. These keys are given as a pair of public key and private key, and the public key given for each group is given as a public key certificate with a digital signature.
The character at the end of the key string, for example, the "2" in the public key KPd2, is a symbol that identifies the crypto engine to which the key is given. In the present embodiment, when the provider is clear, the numbers are expressed as "1", "2", "3", and the key is provided by a key other than the cryptographic engine and the provider is unknown. If not specified, use alphabetic characters such as "x" and "y".
In the present embodiment, the encryption engine 103 of the recording device 100 is identified as "1", the encryption engine 203 of the storage media 200 is identified as "2", and the encryption engine 303 of the playback device 300 is identified. Use each "3" as a symbol.
FIG. 5 shows the internal configuration of the encryption engine 103 of the recording device 100 shown in FIG. The encryption engine 103 includes the certificate verification unit 120, the first encryption unit 121, the random number generation unit 122, the decryption unit 123, the second encryption unit 124, the third encryption unit 125, the certificate holding unit 126, and their components. It is equipped with a local bus 130 that electrically connects at least a part of it.
The certificate verification unit 120 verifies the certificate C [KPd2] obtained from the storage device 200. Certificate C [KPd2] consists of plaintext information including the public key KPd2 (called the "certificate body") and a digital signature attached to the certificate body. This digital signature is the root key Ka of a certificate authority (not shown), which is a third-party organization, based on the result of performing an operation using a hash function on the certificate body (this operation process is called "hash operation"). Data encrypted by. The root key Ka is a private key that is strictly managed by the certificate authority and is the private key of the certificate authority.
The certificate verification unit 120 holds a verification key KPa paired with this root key Ka. This verification key KPa is a public key that verifies the validity of the certificate. Certificate verification is determined by the validity of the certificate and the validity of the certificate.
Confirmation of the validity of the certificate is a process of comparing the calculation result of the hash function for the certificate body of the certificate to be verified and the result of decrypting the digital signature with the verification key KPa. Judge that.
The certificate verification unit 120 keeps a certificate revocation list (called a CRL), which is a list of invalid certificates, and the certificate to be verified in this CRL is the certificate to be verified for the validity of the certificate. If it is not listed, it is judged to be valid.
The process of determining the validity and validity of a certificate and approving the valid certificate in this way is called verification.
When the certificate verification unit 120 succeeds in verification, it takes out the public key KPd2 of the storage device 200 and transmits it to the first encryption unit 121 to notify the verification result. If verification fails, a verification error notification is output.
The certificate holding unit 126 outputs the certificate C [KPd1] of the recording device 100 to the first encryption unit 121. This certificate consists of a certificate body including the public key KPd1 of the recording device 100 and an electronic signature attached to the certificate body. The digital signature is encrypted by the root key Ka of the certificate authority, similar to the certificate of the storage device 200.
The random number generator 122 generates a challenge key Kc1 that is temporarily used for performing encrypted communication with the storage device 200. By generating the challenge key Kc1 with a random number each time encrypted communication is performed, the possibility that the challenge key Kc1 can be detected can be minimized. The generated challenge key Kc1 is transmitted to the first encryption unit 121 and the decryption unit 123.
The first encryption unit 121 uses the public key KPd2 of the storage device 200 retrieved by the certificate verification unit 120 to notify the storage device 200 of the challenge key Kc1 and its own certificate C [KPd1] with the challenge key Kc1. Encrypts its own certificate C [KPd1] to generate challenge information E (KPd2, Kc1 // C [KPd1]).
Here, the symbol "//" indicates data concatenation, and Kc1 // C [KPd1] indicates a data string in which the challenge key Kc1 and the certificate C [KPd1] are arranged side by side. In addition, E indicates an encryption function, and E (KPd2, Kc1 // C [KPd1]) indicates that Kc1 // C [KPd1] is encrypted with KPd2.
The decryption unit 123 decrypts the data encrypted with the challenge key Kc1. Since the session key Ks2 issued by the storage device 200 and the public key KPp2 held by the storage device 200 are encrypted by the challenge key Kc1 and supplied from the storage device 200, the decryption unit 123 generates the random number generator 122. Obtain the challenge key Kc1 and decrypt the session key Ks2 and public key KPp2.
The decrypted public key KPp2 and the session key Ks2 are transmitted to the second encryption unit 124 and the third encryption unit 125, respectively.
The second encryption unit 124 acquires the license data including the content key issued when the encryption device 104 encrypts the content, and uses the license data as the license data provider, that is, the public key KPp2 of the storage device 200. Encrypt. The encrypted license data is transmitted to the third encryption unit 125.
The third encryption unit 125 further encrypts the license data encrypted by the second encryption unit 124 with the session key Ks2 issued by the storage device 200.
In FIG. 5, among the components of the encryption engine 103, the certificate verification unit 120, the first encryption unit 121, the decryption unit 123, and the third encryption unit 125 are electrically connected by the local bus 130, and the local bus It is connected to the data bus 110 of the recording device 100 via 130. Various modification examples can be considered for the form of connecting each component, but in the present embodiment, consideration is given so that the random number generator 122 that generates the challenge key is not directly connected to the data bus 110. As a result, each key used in the encryption engine 103 can be prevented from being leaked to the outside through other components of the recording device 100, and the security can be improved.
FIG. 6 shows the internal configuration of the encryption engine 303 of the reproduction device 300 shown in FIG. The encryption engine 303 includes the certificate output unit 320, the first decryption unit 321, the certificate verification unit 322, the encryption unit 323, the random number generation unit 324, the second decryption unit 325, the third decryption unit 326, and their components. It is equipped with a local bus 330 that electrically connects at least a part of it.
The certificate output unit 320 outputs the certificate C [KPd3] of the playback device 300. The certificate may be held by the certificate output unit 320, or may be held in a certificate holding unit (not shown) and read out. The certificate consists of a certificate body including the public key KPd3 of the playback device 300 and an electronic signature attached to the certificate body. The digital signature is encrypted by the root key Ka of the certificate authority, similar to the certificate of the storage device 200.
The first decryption unit 321 decrypts the data encrypted by the public key KPd3 with the private key Kd3. At the time of playback, the challenge key Kc2 issued by the storage device 200 and the certificate C [KPd2] of the storage device 200 are encrypted by the public key KPd3 of the playback device 300 and supplied from the storage device 200. Part 321 decrypts with its own private key Kd3 and takes out the challenge key Kc2 and the certificate C [KPd2] of the storage device 200.
The retrieved challenge key Kc2 is transmitted to the encryption unit 323, and the certificate C [KPd2] of the storage device 200 is transmitted to the certificate verification unit 322.
The certificate verification unit 322 verifies the certificate C [KPd2] of the storage device 200 retrieved by the first decryption unit 321. Since the detailed processing of verification has been described earlier, the description will be omitted here.
The random number generator 324 generates a session key Ks3 that is temporarily used for encrypted communication with the storage device 200. The generated session key Ks3 is transmitted to the encryption unit 323 and the second decryption unit 325.
The encryption unit 323 encrypts the session key Ks3 and the public key KPp3 with the challenge key Kc2 extracted by the first decryption unit 321 in order to notify the storage device 200 of the session key Ks3 and its own public key KPp3, and the session information. Generate E (Kc2, Ks3 // KPp3).
The second decryption unit 325 decrypts the data encrypted with the session key Ks3. Since the license data is supplied from the storage device 200 as license data that is doubly encrypted by the public key KPp3 and the session key Ks3, the second decryption unit 325 is decrypted by the session key Ks3 generated by the random number generation unit 324. Then, the result is transmitted to the third decoding unit 326.
The third decryption unit 326 decodes the result of the second decryption unit 325 with the private key Kp3 paired with the public key KPp3, and extracts the license data. The extracted license data is transmitted to the decryption device 304, and the decryption device 304 decrypts the encrypted content by using the content key included in the license data.
In the cryptographic engine 303 shown in FIG. 6, various modification examples can be considered in the form of connecting each component, but in the present embodiment, the session key Ks3 generated by the random number generator 324 and the public key are paired. By configuring the private keys Kd3 and Kp3 that form the above so that they do not flow on the data bus 310, the decryption key used in the cryptographic engine 303 is prevented from being leaked to the outside.
FIG. 7 shows the internal configuration of the cryptographic engine 203 of the storage device 200 shown in FIG. These functional blocks can also be realized in various forms by hardware only, software only, or a combination thereof. The encryption engine 203 includes a control unit 220, a random number generation unit 221, a certificate output unit 222, a certificate verification unit 223, a first decryption unit 224, a first encryption unit 225, a second decryption unit 226, and a third decryption unit 237. It includes a second encryption unit 228, a fourth decryption unit 229, a third encryption unit 230, a fourth encryption unit 231 and a local bus 240 that electrically connects at least a part of these components.
The control unit 220 mediates the input / output of data between the control of the internal configuration of the cryptographic engine 203 and the external configuration according to the instruction of the controller 201 of the storage device 200.
The random number generator 221 generates a session key Ks2 or a challenge key Kc2 temporarily used for encrypted communication with the recording device 100 or the playback device 300 by random number calculation. Specifically, when the storage device 200 provides the license data, the challenge key Kc2 is generated, and when the storage device 200 receives the license data, the session key Ks2 is generated.
The certificate output unit 222 outputs the certificate C [KPd2] of the storage device 200. The certificate may be held by the certificate output unit 225, or may be held in a predetermined storage area of the storage device 200, for example, the anti-tamper storage unit 204 and read out. The certificate includes a certificate body containing the public key KPd2 of the storage device 200 and a digital signature attached to the certificate body. The digital signature is encrypted by the root key Ka of the certificate authority.
The certificate verification unit 223 verifies the certificate provided from the outside. Specifically, the certificate C [KPd1] obtained from the recording device 100 and the certificate C [KPd3] obtained from the playback device 300 are verified by the verification key KPa. Since the detailed processing of verification has been described earlier, the description will be omitted here.
The first decryption unit 224 performs a decryption operation for decrypting the data encrypted with its own public key KPd2. Specifically, at the time of recording, the challenge key Kc1 issued by the recording device 100 and the certificate C [KPd1] of the recording device 100 are encrypted by the public key KPd2 of the storage device 200 and supplied from the recording device 100. Therefore, it is decrypted with its own private key Kd2, and the challenge key Kc1 and certificate C [KPd1] are taken out. The extracted certificate C [KPd1] and the challenge key Kc1 are transmitted to the certificate verification unit 223 and the first encryption unit 225, respectively.
The first encryption unit 225 performs an encryption operation for encrypting data with the challenge key Kc1 generated by the recording device 100. Specifically, the session key Ks2 generated by the random number generator 221 and its own public key KPp2 are encrypted with the challenge key Kc1 to generate session information E (Kc1, Ks2 // KPp2).
The second decoding unit 226 performs a decoding operation for decrypting the data encrypted with the session key Ks2 generated by the random number generation unit 221. Specifically, since the license data is supplied from the recording device 100 as encrypted license data that is doubly encrypted by the public key KPp2 and the session key Ks2, this is decrypted by the session key Ks2 and the result is obtained. It is supplied to the third decoding unit 227.
The third decryption unit 227 performs a decryption operation for decrypting the data encrypted with its own public key KPp2. The license data encrypted with the public key KPp2 transmitted from the second decryption unit 226 is decrypted with the private key Kp2 paired with the public key KPp2, and the license data is taken out.
The extracted license data is supplied to the data bus 210 via the local bus 240 and the control unit 220, and is recorded in the anti-tamper storage unit 204 according to the instruction of the controller 201.
The second encryption unit 228 performs an encryption operation for encrypting data with the public key KPd3 of the playback device 100. Specifically, when the license data is provided to the playback device 300, the challenge key Kc2 issued by the random number generator 221 with the public key KPd3 extracted from the certificate C [KPd3] received from the playback device 300. And its own certificate C [KPd2] are encrypted to generate challenge information E (KPd3, Kc2 // C [KPd2]).
The fourth decryption unit 229 performs a decryption operation for decrypting the data encrypted with the challenge key Kc2 issued by the random number generation unit 221. The session information E (Kc2, Ks3 // KPp3) received from the playback device 300 is decrypted with the challenge key Kc2 issued by the random number generator 221, and the session key Ks3 and the public key KPp3 of the playback device 300 are taken out. The extracted session key Ks3 and public key KPp3 are transmitted to the fourth encryption unit 231 and the third encryption unit 230, respectively.
The third encryption unit 230 encrypts the data with the public key KPp3 of the playback device 300. When the license data is provided to the playback device 300, the license data is encrypted with the session key KPp3 received from the playback device 300. The license data is read from the tamper resistant storage unit 204 according to the instruction of the controller 201, and is supplied to the third encryption unit 230 via the data bus 202, the control unit 220, and the local bus 240.
The fourth encryption unit 231 performs an encryption operation for encrypting data with the session key Ks3 issued by the playback device 300. Specifically, the session key Ks3 is used to generate the license data encrypted by the public key KPp3 of the playback device 300 in the third encryption unit 230, and further encrypted license data.
8 and 9 show the procedure for the recording device 100 to record the license data in the storage device 200.
First, the controller 101 of the recording device 100 issues a certificate output command to the storage device 200 (S102). When the controller 201 normally accepts the certificate output command (S104), it orders the cryptographic engine 203 to output the certificate, reads the certificate C [KPd2] from the cryptographic engine 203, and outputs the certificate C [KPd2] to the recording device 100 (S106). ).
When the controller 101 obtains the certificate C [KPd2] from the storage device 200, it sends it to the cryptographic engine 103 of the recording device 100 (S108). When the cryptographic engine 103 receives the certificate C [KPd2] of the storage device 200 (S110), the certificate verification unit 120 verifies the certificate with the verification key KPa (S112). If the certificate is not approved (N in S112), the certificate verification unit 120 sends a verification error notification to controller 101 (S190). When the controller 101 receives the error notification (S192), the controller 101 terminates the process abnormally.
If the certificate is approved (Y in S112), the cryptographic engine 103 generates the challenge key Kc1 by the random number generator 122, and transmits the generated challenge key Kc1 to the first cryptographic unit 121 and the decryption unit 123. The decryption unit 123 holds this challenge key Kc1 internally (S114). The encryption unit 121 encrypts the challenge key Kc1 and its own certificate C [KPd1] with the public key KPd2 of the storage device 200 to generate challenge information E (KPd2, Kc1 // C [KPd1]), and the controller. Send to 101 (S116).
When the controller 101 receives the challenge information E (KPd2, Kc1 // C [KPd1]) (S118), the controller 101 issues a challenge information verification instruction to the storage device 200 (S120).
In the storage device 200, when the controller 201 accepts the challenge information verification instruction (S120), it requests the input of the challenge information E (KPd2, Kc1 // C [KPd1]) (S122).
The controller 101 of the recording device 100 outputs the challenge information E (KPd2, Kc1 // C [KPd1]) to the storage device 200 in response to this request (S124).
When the storage device 200 receives the challenge information E (KPd2, Kc1 // C [KPd1]) (S126), the first decryption unit 224 uses its own private key Kd2 according to the instruction of the control unit 220 in the encryption engine 203. The challenge information E (KPd2, Kc1 // C [KPd1]) is decrypted, and the challenge key Kc1 issued by the recording device 100 and the certificate C [KPd1] of the recording device 100 are taken out (S128).
Then, the extracted certificate C [KPd1] is output to the certificate verification unit 223, and the challenge key Kc1 is transmitted to the first encryption unit 225.
In the encryption engine 202, the certificate verification unit 223 verifies the certificate C [KPd1] transmitted by the verification key KPa according to the instruction of the control unit 220, and transmits the verification result to the control unit 220 (S130). If the certificate is not approved (N in S130), the certificate verification unit 223 notifies the control unit 220 of the verification error notification, and the control unit 220 notifies the controller 201.
Then, the controller 201 transmits to the controller 101 via the storage interface 202 (S194).
When the controller 101 receives the error notification (S192), the controller 101 terminates the process abnormally.
If the certificate is approved (Y in S130), the challenge key Kc1 retrieved by the first decryption unit 224 is held in the first encryption unit 225 (S132).
On the other hand, when the processing of the challenge information verification instruction is completed in the storage device 200, the controller 101 issues a session information generation instruction to the storage device 200 (S134).
In the storage device 200, the controller 201 receives the session information generation instruction (S136), and in the encryption engine 203, the random number generation unit 221 generates the session key Ks2 according to the instruction of the control unit 220, and the generated session key Ks2 is generated. 2 Communicate to decryption unit 226 and first encryption unit 225. Then, the second decoding unit 226 holds this session key Ks2 (S138).
The first encryption unit 225 encrypts the session key Ks2 and its own public key KPp2 with the challenge key Kc1 held in the previous step S132 to generate session information E (Kc1, Ks2 // KPp2) (S140). ).
On the other hand, the controller 101 issues a session information output instruction when the processing of the session information generation instruction is completed in the storage device 200 (S142).
When the storage device 200 receives the session information output instruction (S144), the controller 201 reads the session information E (Kc1, Ks2 // KPp2) from the encryption engine 203 and outputs the session information E (Kc1, Ks2 // KPp2) to the controller 101 of the recording device 100 (S146). ).
When the controller 101 receives the session information E (Kc1, Ks2 // KPp2) from the storage device 200, it sends it to the cryptographic engine 103 (S148). When the cryptographic engine 103 receives the session information E (Kc1, Ks2 // KPp2) from the controller 101 (S150), the decryption unit 123 uses the internal challenge key Kc1 to perform the session information E (Kc1, Ks2 // KPp2). To retrieve the session key Ks2 and the public key KPp2 of the storage device 200 (S152).
Subsequently, the encryption engine 103 encrypts the license data issued by the encryption device 104 with the public key KPp2 of the storage device 200 by the second encryption unit 124. Then, the license data encrypted by the second encryption unit 124 by the third encryption unit 125 is further encrypted by the session key Ks2 issued by the storage device 200 to generate the encryption license data, and the controller 101 Send to (S154).
When the controller 101 receives the encrypted license data (S156), the controller 101 issues a license data write command to the storage device 200 (S158). The license write instruction is accompanied by an address that specifies a recording position on the anti-tamper storage 204. Here, the address indicates a logical address and does not directly specify the recording position in the tamper-resistant storage unit 204, but the data recorded by specifying the address can be read by specifying the same address. It is managed by 201. However, it may be a physical address that directly indicates the position in the anti-tamper storage unit 204.
When the storage device 200 receives the license write command (S160), it requests the input of the encryption license data, and the controller 101 of the recording device 100 outputs the encryption license data to the storage device 200 in response to this request. (S162).
When the storage device 200 receives the encryption license data (S164), it transmits the encryption license data to the second decryption unit 226 in the encryption engine 203.
The second decryption unit 226 decrypts the encrypted license data with the session key Ks2 held internally, and takes out the license data encrypted with its own public key KPp2. Then, the extracted encrypted license data is transmitted to the third decryption unit 227.
The third decoding unit 227 decrypts this with the public key KPp2 and the private key Kp2 paired with it, extracts the license data (S166), and supplies the license data to the data bus 210 via the local bus 240 and the control unit 220.
The controller 201 performs a storage process of recording the license data supplied to the data bus 210 at the designated address of the anti-tamper storage unit 204 (S168).
On the other hand, the controller 101 determines whether or not to continuously record the license data after the processing of the license data writing instruction is completed in the storage device 200 (S170).
When continuously recording the license data (Y in S170), the process proceeds to step S134, and the procedure is started by issuing the session information generation instruction. This is a procedure aimed at reducing the processing by sharing the certificate verification processing when recording a plurality of license data. Here, it is assumed that the license data is continuously recorded, but it is not necessary to record the next license data immediately after recording one license data. The encryption engine 103 and the storage device 200, specifically, the decryption unit 123 of the encryption engine 103 of the recording device 100 and the first encryption unit 225 of the encryption engine 203 of the storage device 200 hold the same challenge key Kc1. Any timing may be used as long as it is in a state.
Further, even when the license data is continuously recorded, there is no problem even if the procedure is started from step S102.
If the license data is not recorded continuously (N of S170), the process ends normally.
By the above procedure, the license data required for decrypting and playing back the encrypted content is recorded in the storage device 200. The encrypted content is normal data, and is directly stored in the normal data recording unit 205 of the storage device 200 by a normal command. The description of the storage process of the normal data will be omitted.
The recording order of the license data and the encrypted content data may be either first. Further, the license data may be recorded by issuing the secure command by dividing the secure command in the free time at the time of recording the encrypted content data.
The procedure until the recording device 100 shown in FIGS. 8 and 9 records the license data in the storage device 200 is an example in the case where the processing proceeds normally.
10 and 11 show the procedure for the playback device 300 to read the license data from the storage device 200.
First, the controller 301 of the playback device 300 requests the encryption engine 303 to output a certificate (S302). When the encryption engine 303 receives this transmission request (S304), the certificate output unit 320 sends the certificate C [KPd3] to the controller 301 (S206). When the controller 301 receives the certificate C [KPd3] from the cryptographic engine 303 (S308), it issues a certificate verification instruction to the storage device 200 (S310).
When the storage device 200 receives the certificate verification instruction (S312), the storage device 200 requests the input of the certificate, and the controller 301 of the playback device 300 responds to this request by receiving the certificate C [KPd3] from the cryptographic engine 303. Output to storage device 200 (S314).
When the storage device 200 receives the certificate C [KPd3] (S316), it transmits the certificate C [KPd3] to the internal cryptographic engine 203. In the encryption engine 202, the certificate verification unit 223 verifies the certificate C [KPd3] with the verification key KPa according to the instruction of the control unit 220 (S318). If the certificate is not approved (N in S318), the certificate verification unit 223 sends a verification error notification to the controller 301 via the control unit 220, the controller 201, and the storage interface 202 (S390). When the controller 301 receives the error notification (S392), the controller 301 terminates the process abnormally. On the other hand, if certificate C [KPd3] is approved (Y in S318), the crypto engine 203 holds the public key KPd3 in the second crypto section 228 (S320).
On the other hand, the controller 301 of the playback device 300 issues a challenge information generation command to the storage device 200 when the certificate C [KPd3] of the encryption engine 303 is approved by the storage device 200 (S322). Then, the storage device 200 receives the challenge information generation instruction (S324). Then, in the encryption engine 202, the random number generation unit 221 generates the challenge key Kc2 according to the instruction of the control unit 220, and transmits the generated challenge key Kc2 to the fourth decryption unit 229 and the second encryption unit 228. Then, the fourth decoding unit 229 holds this challenge key Kc2 internally (S326). Then, the second encryption unit 228 receives its own certificate C [KPd2] from the certification output unit 222, and uses the public key KPd3 held in step S320 to obtain this challenge key Kc2 and its own certificate C [KPd2]. Encrypt and generate challenge information E (KPd3, Kc2 // C [KPd2]) (S328).
On the other hand, the controller 101 issues a challenge information output instruction when the processing of the challenge information generation instruction is completed in the storage device 200 (S330). Then, when the storage device 200 receives the challenge information output command (S332), the controller 201 takes out the challenge information E (KPd3, Kc2 // C [KPd2]) from the encryption engine 203, and the controller 301 of the playback device 300. Output to (S334).
When the controller 301 receives the challenge information E (KPd3, Kc2 // C [KPd2]), it sends it to the cryptographic engine 303 (S336). Then, when the cryptographic engine 303 receives the challenge information E (KPd3, Kc2 // C [KPd2]) (S338), the first decryption unit 321 in the cryptographic engine 303 receives the challenge information E (KPd3, Kc2 // C). [KPd2]) is decrypted with its own private key Kd3, and the challenge key Kc2 and certificate C [KPd2] are extracted (S340). Subsequently, in the cryptographic engine 303, the certificate verification unit 322 verifies the certificate with the verification key KPa (S342). If the certificate is not approved (N in S342), the certificate verification unit 322 sends a verification error notification to controller 301 (S394). When the controller 301 receives the error notification (S392), the controller 301 terminates the process abnormally.
On the other hand, if the certificate is approved (Y of S342), the extracted challenge key Kc2 is held by the encryption unit 323 (S344).
On the other hand, the controller 301 issues a license read instruction to the storage device 200 (S346). The license read instruction is accompanied by an address that specifies the read position in the anti-tamper storage unit 204. When the storage device 200 receives the license read command (S348), the storage device 200 reads the license data stored in the designated address of the tamper resistant storage unit 204, and the read license data is the third encryption unit of the encryption engine 202. Held by 230 (S350).
On the other hand, the controller 301 requests the encryption engine 303 to transmit the session information (S352). When the encryption engine 303 receives this transmission request (S354), in the encryption engine 303, the random number generator 324 generates the session key Ks3 and transmits it to the encryption unit 323 and the second decryption unit 325. The second decryption unit 325 holds this session key Ks3 internally (S354). Then, the encryption unit 323 encrypts the session key Ks2 generated by the random number generation unit 324 and its own public key KPp3 with the challenge key Kc2 held internally in step S344, and the session information E (Kc2, Ks3 // KPp3). Is generated and sent to controller 301 (S356). When the controller 301 receives the session information E (Kc2, Ks3 // KPp3) from the encryption engine 303 (S358), the controller 301 issues a session information processing instruction to the storage device 200 (S360).
When the storage device 200 receives the session information processing instruction (S362), the storage device 200 requests the input of the session information, and the controller 301 of the playback device 300 receives the session information E (Kc2, Kc2,) received from the encryption engine 303 in response to this request. Output Ks3 // KPp3) to the storage device 200 (S364). When the storage device 200 receives the session information E (Kc2, Ks3 // KPp3) (S366), it transmits this to the fourth decryption unit 229 of the encryption engine 203. The fourth decoding unit 229 decodes the transmitted session information E (Kc2, Ks3 // KPp3) with the challenge key Kc2 held in step S326 (S368). Then, the public key KPp3 of the reproduction device 300 and the session key Ks3 issued by the reproduction device 300 are taken out and transmitted to the third encryption unit 230 and the fourth encryption unit 231, respectively. Next, the third encryption unit 230 encrypts the license data held internally in step S350 with the transmitted public key KPp3 of the playback device 300, and transmits the license data to the fourth encryption unit 231. When the license data encrypted with the public key KPp3 is transmitted, the fourth encryption unit 231 encrypts it with the session key Ks3 transmitted from the fourth decryption unit 229 to generate the encryption license data (S370). ).
On the other hand, the controller 101 issues an encryption license output instruction when the processing of the session information processing instruction is completed in the storage device 200, that is, when the encryption license data is generated (S372). When the storage device 200 receives the encryption license output command (S374), the controller 201 extracts the encryption license data from the encryption engine 203 and outputs the encryption license data to the controller 301 of the playback device 300 (S376).
When the controller 301 receives the encryption license data from the storage device 200, it sends it to the encryption engine 303 (S378). When the encryption engine 303 receives the encryption license data (S380), the second decryption unit 325 decrypts the encryption license data with the session key Ks3 held in step S354 (S382) and sends the encryption license data to the third decryption unit 326. The third decryption unit 326 decrypts the private key Kp3 paired with the public key KPp3 and retrieves the license data (S382). Then, the license data is sent to the decryption device 304 (S384), and the decryption device 304 is used when decrypting the encrypted content data. By the above procedure, the license data for decrypting the encrypted content is read from the storage device 200 by the playback device 300.
On the other hand, when the controller 301 wants to read other license data after reading the license data in the storage device 200 (Y in S386), the controller 301 proceeds to step S346 and starts the procedure from issuing the license read command. be able to. This is a procedure aimed at reducing the processing by sharing the certificate verification processing when reading a plurality of license data. Although it is assumed that the license data is continuously read, it is not necessary to read one license data and then immediately perform the next reading. The encryption engine 303 and the storage device 200, specifically, the encryption unit 323 of the encryption engine 303 of the playback device 300 and the fourth decryption unit 229 of the encryption engine 203 of the storage device 200 hold the same challenge key Kc2. Any timing may be used as long as it is in a state. Further, even when the license data is continuously read, there is no problem even if the procedure is started from step S302. Subsequently, if no other license data is read (N of S386), the controller 303 ends the normal process.
Copy or move the license data recorded in the storage device 200 to another storage device (license data recorded in the storage device 200 is available) or move (the license data recorded in the storage device 200 is deleted or invalidated). The process of recording can be provided. If the other storage media that newly records the license data has the same function, transfer the license between the storage devices by the same procedure, and transfer the license from the storage device 200 to another storage device with the same function. It is clear that the license can be recorded. In this case, the transfer of the license from the storage device 200 to the other storage device is performed by using the license from the storage device 200 to the playback device 300 and by transferring the license from the other storage device to the storage device 200. It functions in the same manner as recording a license from the recording device 100 to the storage device 200.
According to the above embodiment, the destination of the license data (storage device 200 at the time of recording, the playback device 300 at the time of reading) is the destination of the license data (storage device 200 at the time of recording, the playback device 300 at the time of reading). After verifying the certificate C [KPdx] (hereinafter, x is the destination of the license data and y is the source of the license data), the source certificate C [KPdy] of the license data is used as the challenge information E (KPdx, Kcy). If the sender's device is verified as valid by sending it from the sender to the destination as // C [KPdy]) and verifying this sender certificate C [KPdy] at the destination. When the license data is provided and the source device is verified to be invalid, it is possible to refuse the provision of the license data.
Here, since the source certificate C [KPdy] is encrypted together with the challenge key Kcy by the destination public key KPdx, for example, assuming that the source certificate C [KPdy] is replaced and the challenge information is replaced. However, the exchange of the challenge key Kcy is not established. This is because the source certificate C [KPdy] is sent from the source to the destination in association with the procedure for exchanging the challenge key Kcy.
As the challenge information, in addition to the above embodiment, the same effect can be obtained by using E (KPdx, Kcy) // E (Kcy, C [KPdy]) for encrypting the source certificate C [KPdx] with the challenge key Kcy. Can be obtained.
Also. As explained earlier, the certificate C [KPdy] contains the certificate body (denoted as Cbody [KPdy]), which is the plain data including the public key KPdy, and the signature data (Csig [KPdy]) for the Cbody [KPdy]. It is configured by concatenating). That is, the certificate C [KPdy] = Cbody [KPdy] // Csig [KPdy]). And the tampering of Cbody [KPdy] is discovered by checking Csig [KPdy].
Considering this characteristic, the same effect can be obtained even if the encryption processing performed on C [KPdy] is performed only on Csig [KPdy] which is a part of C [KPdy]. In this case, the challenge information is E (KPdx, Kcy // Csig [KPdy]) // C [KPdy] or E (KPdx, Kcy) // E (Kcy, Csig [KPdy]) // C [KPdy] ].
By doing so, the amount of data to be encrypted is reduced, and the processing can be reduced as compared with the case where the entire certificate C [KPdy] is encrypted.
Furthermore, instead of encrypting the certificate C [KPdy] or its part Csig [KPdy], the digital signature data can be attached and sent by a keyed hash using the challenge key Kcy. In this case, assuming that the function H indicates the operation result by the hash function, the challenge information is, for example, E (KPdx, Kcy) // C [KPdy] // H (Kcy // C [KPdy]), or , E (KPdx, Kcy) // C [KPdy] // H (Kcy // Csig [KPdy]).
Here, the verification process when the challenge information is E (KPdx, Kcy) // C [KPdy] // H (Kcy // C [KPdy]) will be described. At the destination, Kcy and C [KPdy] are extracted from the challenge information, and H (Kcy // C [KPdy]) is calculated independently. Then, H (Kcy // C [KPdy]) extracted from the challenge information is compared, and if both match, it is determined that the issuer of the challenge key Kcy and the provider of the certificate C [KPdy] are the same. Then, move on to the verification of C [KPdy] of the certificate and follow the verification result.
If they do not match, it is determined that the issuer of the challenge key Kcy and the provider of the certificate C [KPdy] are different or have been tampered with, and the certificate C [KPdy] is not approved regardless of the verification result. And.
When the challenge information is E (KPdx, Kcy) // C [KPdy] // H (Kcy // CSig [KPdy]), the same verification process is performed except that the target of the hash function is different. (Second Embodiment) FIG. 12 shows the configuration of the recording / reproducing device 400 according to the second embodiment. In the present embodiment, the recording device 100 and the playback device 300 in the first embodiment are realized as one recording / playback device 400.
The recording / reproducing device 400 of the present embodiment includes a controller 401, a storage interface 402, a recording unit 403, a reproduction unit 404, and a local bus 410 that electrically connects at least a part of these components.
The recording unit 403 has a configuration of the recording device 100 according to the first embodiment shown in FIG. 2, and the reproducing unit 404 has a configuration of the reproducing device 300 according to the first embodiment shown in FIG. In this figure, the same reference numerals are given to the same configurations as those in the first embodiment.
The first cryptographic engine 103 corresponds to the cryptographic engine 103 of the recording device 100 in the first embodiment, and the second cryptographic engine 303 corresponds to the cryptographic engine 303 of the playback device 300 in the first embodiment. The internal configuration of the first cryptographic engine 103 is the same as that of the cryptographic engine 103 of the first embodiment shown in FIG. 5, and the internal configuration of the second cryptographic engine 303 is the same as that of the first embodiment shown in FIG. It is the same as the internal configuration of the cryptographic engine 303 of the form.
The controller 401 has the functions of both the controller 101 of the recording device 100 and the controller 301 of the playback device 300 in the first embodiment.
The storage interface 402 controls the input / output of data to and from the storage device 200, and the data bus 410 electrically connects the configuration of the recording / playback device 400.
The operation of the recording / reproducing device 400 in the present embodiment is also the same as the operation in the first embodiment, and in the operation described in the first embodiment, the recording device 100 and the reproducing device 300 are recorded / reproduced in the recording / reproducing device 400. It is similar to the controller 101 and 301 replaced by the controller 401, the storage interfaces 102 and 302 replaced by the storage interface 402, and the data buses 110 and 310 replaced by the data bus 410, respectively.
In the present embodiment, the recording unit 403 and the playback unit 404 include the first cryptographic engine 103 and the second cryptographic engine 303, respectively, but they may be configured to share the same functional block in these cryptographic engines. In this case, the configuration is the same as that of the encryption engine 203 in the storage device 200 shown in FIG. 7 in the first embodiment. (Third Embodiment) FIG. 13 shows the configuration of the content distribution system according to the third embodiment. In the present embodiment, the recording device 100 in the first embodiment is realized as a distribution server 500 for distributing the content and a terminal device 520 for receiving the provision of the content. In this figure, the same components as those of the recording device 100 in the first embodiment are designated by the same reference numerals.
The distribution server 500 includes a cryptographic engine 103, a communication device 502, a content database 503, a license database 504, a user database 505, a controller 501 that controls them, and a data bus 510 that electrically connects them.
The terminal device 520 includes a controller 101, a storage interface 102, a communication device 521, and a data bus 522 that electrically connects them.
The distribution server 500 and the terminal device 520 are connected to each other via the communication devices 502 and 521, respectively, by the Internet 20 as an example of the network.
The cryptographic engine 103 of the distribution server 500 has the same function as the cryptographic engine 103 of the first embodiment, and the controller 101 and the storage interface 102 of the terminal device 520 are the controller 101 and the controller 101 of the first embodiment, respectively. It has the same function as the storage interface 102.
The content database 503 holds the content to be provided to the user. The license database 504 holds license data, including a content key used to encrypt the content. In the present embodiment, the content is already encrypted by the content key and stored in the content database 503, but the content before being encrypted is stored in the content database 503, and the first distribution server 500 stores the content. The content encoder 105 and the encryption device 104 provided in the recording device 100 of the embodiment may be further provided, and the content may be read from the content database 503, encoded, and encrypted.
The user database 505 holds information on the user to whom the content is provided. For example, the user's personal information, the address of the user's terminal device 520, the content purchase history, the billing information, and the like may be retained.
The controller 501 reads the encrypted content from the content database 503 in response to the user's request and provides the encrypted content to the user. Then, when the license data for decrypting the content is provided to the user by the encryption engine 103, the user database 155 is updated in order to charge the consideration for providing the content.
In the present embodiment, if the data bus 510, the communication device 502, the Internet 20, the communication device 521, and the data bus 522 are the data bus 110 in the first embodiment in which the configurations are electrically connected, the first The configuration is the same as that of the first embodiment.
The procedure of the cryptographic input / output processing of the present embodiment is the same as that of the first embodiment.
In the present embodiment, since the communication between the encryption engine 103 and the controller 101 is performed via the Internet 20, the communication is performed in the same device. As described with reference to FIGS. 8 and 9, since data is always encrypted and transmitted / received between the encryption engine 103 and the controller 101, high tamper resistance can be realized.
The content can be reproduced by attaching the storage device 200 to the reproduction device 100 in the first embodiment or the recording / reproduction device 300 in the second embodiment. Further, the terminal device 520 may be configured to include the reproduction unit 404 of the recording / reproduction device 300 according to the second embodiment, so that reproduction may be performed.
Although the embodiment according to the present invention has been described above, this embodiment is an example, and the present invention is not limited to this embodiment, but may be a combination of each component or each processing process. It will be understood by those skilled in the art that various modifications are possible and that such modifications are also within the scope of the present invention.
For example, in the above embodiment, the functional block for encryption and the functional block for decryption are provided separately in the encryption engine, but the circuit may be shared by these components. As a result, the circuit scale can be suppressed, which can contribute to miniaturization and low power consumption.
The embodiments of the present invention can be appropriately modified in various ways within the scope of the technical idea shown in the claims.
<figref num="1">It is a figure which shows the whole structure of the data recording / reproduction system which concerns on 1st Embodiment.</figref><figref num="2">It is a figure which shows the internal structure of the recording apparatus which concerns on 1st Embodiment.</figref><figref num="3">It is a figure which shows the internal structure of the reproduction apparatus which concerns on 1st Embodiment.</figref><figref num="4">It is a figure which shows the internal structure of the storage device which concerns on 1st Embodiment.</figref><figref num="5">It is a figure which shows the internal structure of the cryptographic engine shown in FIG.</figref><figref num="6">It is a figure which shows the internal structure of the cryptographic engine shown in FIG.</figref><figref num="7">It is a figure which shows the internal structure of the cryptographic engine shown in FIG.</figref><figref num="8">It is a figure which shows the procedure until the recording device records the license data in a storage device.</figref><figref num="9">It is a figure which shows the procedure until the recording device records the license data in a storage device.</figref><figref num="10">It is a figure which shows the procedure until the reproduction device reads the license data from a storage device.</figref><figref num="11">It is a figure which shows the procedure until the reproduction device reads the license data from a storage device.</figref><figref num="12">It is a figure which shows the internal structure of the recording / reproduction apparatus which concerns on 2nd Embodiment.</figref><figref num="13">It is a figure which shows the internal structure of the recording / reproduction apparatus which concerns on 3rd Embodiment.</figref>
Code description
100 Recording device 200 Storage device 300 Playback device 400 Recording / playback device 500 Distribution server 520 Terminal device
14 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2015525545A | Cited by | Japan | Search report |
| JP2017192134A | Cited by | Japan | Search report |
| JP2015525545A | Cited by | Japan | Search report |
| US9537663B2 | Cited by | United States of America | Applicant |
1 member in 1 office
Members1
| Document | Office | Kind | |
|---|---|---|---|
| JP2006033765AThis record | Japan | A |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Notification of change of attorneyJAPANESE INTERMEDIATE CODE: A7421RD01 | RD01 |
Numbers
- Publication
- 2006033765
- Application
- 213671
Titles2
- Japanese
- コンテンツ利用情報提供装置およびコンテンツ利用情報享受装置
- English
- Content usage information providing device and content usage information enjoying device
Classification
- IPC, 8
- H04L9 08
- G06F21 00
- G06F21 44
- G06F21 60
- G06F21 62
- G06F21 64
- H04L9 32
- G06F21 24