Data copyright management system
Abstract
This record has no abstract on file.
Term
Term ended
Expired 13 October 2025, 0.9 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
5 claims: 4 independent, 1 dependent
- 1Multiple dataIt is a data copyright management system when creating new data by processingA database that stores multiple data and a private key for the data,SaidMultiple encrypted data obtained from the database, SaidSupplied from the databasePrivate keyCreate new data by decoding usingThe first user terminal to doA second user terminal that uses the new data,A copyright management center that manages data copyrights,A data copyright management system that includes The first userTerminalIs、Multiple encrypted dataWhen、A machining program for creating the new dataDigitally signedMachining programAs a permission keySecondA userTerminalSupply toThe plurality ofEncrypted dataAnd a digitally signed machining programThe second user who receivedThe terminal isDigitally signedMachining programToSaidPresent it to the copyright management center and apply for use, and the copyright management center、First user who is a processor by digital signatureTerminalConfirm that the processor is the first userTerminalWhen it is confirmed that, SecondA userTerminalFor use againstsecretProvide the keyData copyright management system。 複数のデータを加工することにより新しいデータを作成する場合のデータ著作権管理システムであって、複数のデータと、該データ用の秘密鍵を格納するデータベースと、前記データベースから入手した複数の暗号化されたデータを、前記データベースから供給された秘密鍵を用いて復号し、前記復号されたデータを加工することにより新しいデータを作成する第1のユーザ端末と、前記新しいデータを利用する第2のユーザ端末と、データの著作権を管理する著作権管理センタと、を含むデータ著作権管理システムであって、 前記第1のユーザ端末は、複数の暗号化されたデータと、前記新しいデータを作成するための加工プログラムであってディジタル署名された加工プログラムを利用許可鍵として第2のユーザ端末に供給し、前記複数の暗号化されたデータと、ディジタル署名された加工プログラムを受け取った前記第2のユーザ端末は、ディジタル署名された加工プログラムを前記著作権管理センタに提示して利用申込を行い、 前記著作権管理センタは、ディジタル署名によって加工者である第1のユーザ端末を確認し、加工者が第1のユーザ端末であることが確認された場合に、第2のユーザ端末に対して利用のための秘密鍵を提供するデータ著作権管理システム。
- 2In the data copyright management system described in claim 1,When the second user terminal presents a digitally signed processing program to the copyright management center, the secondary copyright for the new data generated at the first user terminal is registered in the copyright management center. Rights management system. 請求項1記載のデータ著作権管理システムにおいて、前記第2のユーザ端末がディジタル署名された加工プログラムを著作権管理センタに提示するときに、第1のユーザ端末で発生した新しいデータに関する2次著作権が著作権管理センタに登録されるデータ著作権管理システム。
- 4In the data copyright management system according to any one of claims 1, 2, or 3.The first user terminal is a data copyright management system that creates new data by using a part of each data among a plurality of decrypted data. 請求項1、2、又は3のうちいずれか1項に記載のデータ著作権管理システムにおいて、前記第1のユーザ端末は、復号された複数のデータのうち各データの一部を使用することにより新しいデータを作成するデータ著作権管理システム。
- 5In the data copyright management system according to any one of claims 1, 2, 3, or 4.When requesting the use of a plurality of data in the database, the first user terminal presents the public key of the first user terminal to the database.The database is a data copyright management system that encrypts a private key for data with a public key of a first user terminal and supplies the encrypted private key to the first user terminal. 請求項1、2、3、又は4のうちいずれか1項に記載のデータ著作権管理システムにおいて、前記第1のユーザ端末は、データベース内の複数のデータの使用を要求するときに、第1のユーザ端末の公開鍵をデータベースに提示し、前記データベースは、データ用の秘密鍵を第1のユーザ端末の公開鍵で暗号化し、該暗号化された秘密鍵を第1のユーザ端末に供給するデータ著作権管理システム。
Independent claims4
142 paragraphs, as filed
The present invention relates to a system for managing copyright in the use of digital data, that is, in display, store, copy, edit, and transmit, and in particular, a multimedia system. It is considered to be used for.
In today's information age, database systems are becoming widespread in which various types of data stored independently by each computer are used by connecting each computer via a communication line. The information handled so far by this database system is coded information with a small amount of information that can be processed by a classical computer and monochrome binary data such as facsimile information at best, natural images and moving images. It was not possible to handle data with an extremely large amount of information such as.
By the way, with the development of digital processing technology for various electric signals, the development of digital processing technology for image signals other than binary data, which was conventionally treated only as analog signals, is being promoted.
Since the digitization of this image signal makes it possible for a computer to handle an image signal such as a television signal, a "multimedia system" that simultaneously handles various data handled by the computer and image data obtained by digitizing the image signal. Is attracting attention as a future technology.
Since image data has an overwhelmingly large amount of information as compared with character data and voice data, it is difficult to store, transfer, or perform various processes in a computer as it is.
Therefore, it is conceivable to compress / decompress these image data, and several standards for image data compression / decompression have been created. Among them, JPEG (Joint Photographic image coding Experts Group) standard for still images, H.261 standard for television conferences, and MPEG1 (Moving Picture image coding Experts Group 1) for image storage have been used as common standards. The MPEG2 standard for high-definition television broadcasting has been created from the standard and current television broadcasting. These technologies have enabled real-time processing of digital video data.
Since the quality of analog data, which has been widely used in the past, deteriorates every time it is stored, copied, processed, or transferred, the copyright processing caused by these operations has not become a major problem. However, since the quality of digital data does not deteriorate even if it is repeatedly stored, copied, processed, and transferred, the copyright processing caused by these operations is a big problem.
Until now, there has been no accurate method for copyright processing of digital data, and it is processed by the Copyright Law or by contract, and the Copyright Law also institutionalizes compensation for digital recording equipment. It's just that.
The usage of the database is not just to refer to the contents, but usually to make effective use of the obtained data by saving, copying, and processing, and transferring the processed data to another person by copying or transferring, or even to the database. It is transferred to the data and registered as new data.
In the conventional database system, only character data was handled, but in the multimedia system, in addition to the data such as characters that have been stored in the database so far, audio data and image data that are originally analog data are handled. Is digitized into a database.
In such a situation, how to handle the copyright of the data stored in the database becomes a big problem, but so far, the copyright management means for that purpose, especially the secondary use such as copying, processing, and transfer. There is no complete rights management measure for.
The present inventors have described a system in which copyright management is performed by obtaining a permit key from a key management center through a public telegraph telephone line in JP-A-6-46419 and JP-A-6-141004. -No. 132916 proposed a device for that purpose.
In addition, in Japanese Patent Application No. 6-64889, by further developing these above-mentioned prior inventions, the primary display (including audio conversion), storage, etc. of digital data in a database system including real-time transmission of digital video We proposed a copyright management method for secondary use such as use and copying, processing, and transfer.
In this prior application, the database copyright management method is a program for managing copyrights, in addition to the key that permits the use to be sent to the applicant for use in the database system in order to manage the copyright. Use rights information. The copyright management program monitors and manages the usage so that it is not used contrary to the application or permission contents.
In addition, the present inventors specifically applied the database copyright management method proposed in the above-mentioned Japanese Patent Application No. 6-64889, which is a prior application, to the database copyright management system. Proposed in the issue.
The system proposed in this Japanese Patent Application No. 6-237673 consists of a database copyright management system consisting of a key management center that manages encryption key K and a copyright management center that manages database copyright. All are encrypted by the first encryption key K1, and the primary user who uses the data directly from the database presents the primary user's information I1 to the key management center and the key corresponding to the usage pattern. The key management center that made the request for K and received the primary usage application from the primary user transfers the information I1 of the primary user to the copyright management center, and the copyright management center that received the information of the primary user is this. The copyright management program Pc is transferred to the key management center together with the information I1, and the key management center that receives the copyright management program Pc is the first encryption key (cryptkey) K1 corresponding to the copyright management program Pc and the usage pattern. The 2nd encryption key K2 is transferred to the primary user via the communication network, and the primary user who receives the 1st encryption key decrypts the data using the received 1st encryption key K1 ( decrypt) When data is saved, copied, or transferred thereafter, encryption and decryption are performed using the second encryption key K2.
In the cryptographic technology, the case where the plaintext M is encrypted using the encryption key K to obtain the ciphertext C is expressed as C = E (K, M), and the ciphertext C is decrypted using the encryption key K to obtain the plaintext M. The case of obtaining is expressed as M = D (K, C), and this expression will be used hereafter in this specification as well.
When the data is copied to an external storage medium without being saved or transferred, the first encryption key K1 and the second encryption key K2 are discarded, and when the primary user uses the data again, the copyright management center The first encryption key K1 and the second encryption key K2 were reissued from, and it was confirmed that the data was copied or transferred to the secondary user by receiving the reissuance of the second encryption key K2. This is recorded in the copyright management center.
The secondary user presents the information I1 of the primary user and the information I0 about the original copyright to the copyright management center when applying for the secondary use to the copyright management center.
The copyright management center uses the second encryption key (viewing permission key) K2 and the third encryption key (permission key corresponding to the usage pattern) K3 and the copyright management program Pc encrypted together with the permission key Kp corresponding to the usage pattern. Send to secondary user.
Typical methods used in data encryption include a secret key cryptosystem (Secret Key Crypto System) and a public key cryptosystem (Public Key Crypto System).
The private key method is a cryptographic method that uses the same private encryption key Ks for encryption and decryption. Cmks = E (Ks, M) M = D (Ks, Cmks)
In public key cryptography, the encryption key is the public key (Public Key) K.<sup>B </sup>It is an encryption key system in which the decryption key is not disclosed, the encryption key is called the public key, and the decryption key is the private key (Private Key) K.<sup>V </sup>Is called. To use this encryption method, the data sender encrypts with the public key Kb of the receiver, and the Cmkb = E (Kb, M) data receiver uses the private key Kv that is not public. Decrypt. M = D (Kv, Cmkb)
In the application submitted at the same time as the present application, the present inventors use the first public key Kb1, the first public key Kb1 corresponding to the first public key Kb1, the second public key Kb2, and the second public key Kb2 prepared by the user. The corresponding second private key Kv2, the first private key Ks1 and the second private key Ks2 prepared by the database side are used, and on the database side, the data M is encrypted using the first private key Ks1 and Cmks1 = E (Ks1). , M) The first private key Ks1 is further encrypted using the first public key Kb1 Cks1kb1 = E (Kb1, Ks1), and the second private key Ks2 is encrypted using the second public key Kb2, and Cks2kb2 = E (Kb2, Ks2) Send these encrypted data Cmks1, encryption 1st private key and Cks1 and encryption 2 private key Cks2kb2 to the user.
On the user side, the encrypted first private key Cks1kb1 is decrypted using the first dedicated key Kv1, and the encrypted data Cmks1 is decrypted using the decrypted first private key Ks1 with Ks1 = D (Kv1, Cks1kb1). While using M = D (Ks1, Cmks1), the second encrypted private key Cks2kb2 is decrypted with the second dedicated key Kv2, and the second private key Ks2 decrypted with Ks2 = D (Kv2, Cks2kb2) is decrypted or later. We are proposing an invention to be used as an encryption key when storing, copying, and transferring data in.
<p> By the way, the database copyright management system proposed so far in the above-mentioned Japanese Patent Application No. 6-237673 etc. assumes that the data or database used is single, and uses multiple data or databases. It is not supposed to process and create new data.</p><p> Therefore, in this application, we propose a data copyright management system that assumes that a plurality of data obtained from a single database or a plurality of data obtained from a plurality of databases are used for processing to create new data.</p>
<p> In this system, when new data is created by processing multiple encrypted data obtained from the database, encrypted and supplied to others, the encryption key and processing of each of the multiple data as raw materials are processed. The data digitally signed in the processing program, which is a process, is used as the usage permission key.</p><p> When the user who receives the processed and encrypted data presents the digitally signed data to the copyright management center and applies for use, the copyright management center confirms the processor by the digital signature, and the processor processes the data. Only when it is confirmed that the user is a legitimate user of the data, the key for use is provided to the user.</p><p> In yet another system, a primary user who wishes to use the original data encrypted and supplied using the primary encryption key requests the key management center to distribute the primary usage key, and the key management center Distributes the primary usage key to the primary user and charges for it.</p><p> The primary user decrypts and uses the encrypted data using the primary encryption key included in the primary usage key, but when the decrypted data is stored in the primary user's device, the primary usage key is used. Re-encrypted using.</p><p> The primary user who wishes to process the data requests the key management center to distribute the secondary key for processing the data, and the key management center distributes the secondary key to the primary user. The primary user who receives the secondary usage key makes a copy of the primary copyright data, processes the duplicated data, and the decrypted secondary data in the middle of processing is included in the secondary usage key. It is encrypted with an encryption key, and the final processed data is encrypted with a third encryption key and stored in the device of the primary user. The primary user registers the third encryption key in the key management center in order to exercise the secondary exploitation right for data processing of the secondary copyright data, and the encrypted secondary data is used as the third encryption key. It is encrypted using it and supplied to a secondary user by copying it to an external storage medium or transferring it via a network system.</p><p> The secondary user who wishes to use the encrypted secondary data requests the key management center to distribute the third encryption key, and the key management center distributes the third encryption key to the secondary user.</p><p> The secondary user who receives the secondary encryption key decrypts the encrypted secondary data using the secondary encryption key and uses it.</p>
Examples of the present invention will be described with reference to the drawings.
FIG. 1 is a configuration diagram of a data copyright management system according to the present invention. The data stored in the database in this system is not encrypted.
The embodiment shown in the prior application, Japanese Patent Application No. 6-237673, uses satellite broadcasting or a recording medium in addition to the database as a means for supplying data. On the other hand, the examples shown here show only the database as a means of supplying data for the sake of brevity. However, it goes without saying that the present invention can also be applied to the case where satellite broadcasting, terrestrial broadcasting, CATV broadcasting or recording media that do not need to be encrypted free of charge, such as those with advertisements, are used as data supply means other than the database. is there.
When the data obtained by the primary user is copied as it is and supplied to the secondary user, the copyright of the primary user does not occur in the data because no changes have been made to the data. However, if new data is created based on the data obtained by the primary user, or if new data is created by combining with other data, the new data will be secondary to the primary user. Copyright occurs.
In addition, when the secondary user creates new data based on the data obtained from the primary user, or when new data is created by combining with other data, the new data is similarly described as 2 Secondary copyright of the next user occurs.
In the embodiment shown in this figure, 1, 2 and 3 are databases in which text data, computer graphics screen or computer program binary data, audio data or video data are stored unencrypted, and 9 is communication. Public line provided by the operator or communication line such as CATV line provided by the cable television operator, 4 is the primary user terminal device, 5 is the secondary user terminal device, 6 is the tertiary user terminal device, 7 is n Next user terminal device. In addition, 8 is a copyright management center that manages data copyrights.
Of these, databases 1, 2, 3, copyright management center 8, primary user terminal device 4, secondary user terminal device 5, tertiary user terminal device 6, and nth user terminal device 7 are connected to the communication line 9. ing.
In this figure, the route shown by the broken line is the route through which the encrypted data is transmitted, and the route shown by the solid line is from each user terminal device 4, 5, 6, 7 to each database 1, 2, 3, And the route in which the request to the copyright management center 8 is transmitted, and the route indicated by the one-point chain line is each database 1,2,3 and each user terminal device 4,5,6, from the copyright management center 8. 7 This is the route through which the authorization key, copyright management program, and encryption key corresponding to the usage pattern are transmitted.
In this embodiment, the first public key Kb1 prepared by the user, the first private key Kv1 corresponding to the first public key Kb1, the second public key Kb2, and the second private key Kv2 corresponding to the second public key Kb2, The first private key Ks1 and the second private key Ks2 prepared by the database are used.
In the database, data M is encrypted using the first private key Ks1 and Cmks1 = E (Ks1, M) and the first private key Ks1 is encrypted using the first public key Kb1 Cks1kb1 = E (Kb1, Ks1) At the same time, the second private key Ks2 is encrypted using the second public key Kb2, and Cks2kb2 = E (Kb2, Ks2) These encrypted data Cmks1, the first encrypted private key Cks1kb1 and the second encrypted private key Cks2kb2 are used by the user. Send to.
On the user side, the encrypted first private key Cks1kb1 is decrypted using the first dedicated key Kv1, and the encrypted data Cmls1 is decrypted using the decrypted first private key Ks1 with Ks1 = D (Kv1, Cks1kb1). While using M = D (Ks1, Cmks1), the encrypted second private key Cks2kb2 is decrypted using the second dedicated key Kv2, and Ks2 = D (Kv2, Cks2kb2) decrypted second private key Ks2 is It is used as an encryption key when saving, copying, and transferring data after decryption.
When the data obtained by the primary user 4 is copied as it is and supplied to the secondary user 5, no change is made to the data, so that the data is not copyrighted by the primary user 4. However, if new data is created based on the data obtained by the primary user 4, or if new data is created by combining with other data, the new data will be the secondary of the primary user 4. A copyright is generated, and this primary user becomes the original copyright holder of the secondary work.
Similarly, when the secondary user 5 creates new data based on the data obtained from the primary user 4, or when the secondary user 5 creates new data by means such as combining with other data, the same applies. A secondary copyright of the secondary user 5 is generated for the new data, and this secondary user 5 becomes the original copyright holder of the secondary work.
Text data, computer graphics screen or computer program binary data, digital audio data, and digital video data are stored in each database 1, 2, and 3 in response to a request from the primary user terminal device 4. It is supplied to the primary user terminal device 4 via the communication line 8 in an encrypted state at the time of reading.
The copyright of the data obtained from the database is managed by the method described in the prior application, Japanese Patent Application No. 6-237673, or the method described in the application submitted at the same time as the present application.
The outline of the method proposed by the present inventors in other applications is shown.
Both the private key method and the public key method are adopted as the encryption method. If the public key method is used for data encryption, the security of the encrypted data will be improved, but if the data with a large amount of information is encrypted with the public key method, the time required to decrypt the data will be enormous. It becomes a thing and is not practical.
However, since the key used for encryption is used by humans, the amount of information is not so large unlike the amount of data information.
In this copyright management system, the first public key Kb1 prepared by the user, the first private key Kv1 corresponding to the first public key Kb1, the second public key Kb2, and the second private key corresponding to the second public key Kb2 are provided. The first private key Ks1 and the second private key Ks2 prepared by Kv2 and the database are used.
In the database, data M is encrypted using the first private key Ks1 and Cmks1 = E (Ks1, M) encryption. The first private key Ks1 is further encrypted using the first public key Kb1. Cks1kb1 = E (Kb1) , Ks1) and the second private key Ks2 are encrypted using the second public key Kb2, and Cks2kb2 = E (Kb2, Ks2) these encrypted data, the first encrypted private key Cks1kb1 and the second encrypted private key Cks2kb2 To the user.
On the user side, the first encrypted private key Cks1kb1 is decrypted using the first dedicated key Kv1, and Ks1 = D (Kv1, Cks1kb1) is decrypted. The encrypted data Cmks1 is decrypted with the first private key Ks1 and M = D. While using (Ks1, Cmks1), the second encrypted private key Cks2kb2 is decrypted using the second dedicated key Kv2, and Ks2 = D (Kv2, Cks2kb2) decryption The second private key Ks2 is the data after decryption. Used as an encryption key for storage, copying, and transfer.
With reference to FIG. 2, it will be described that processing is performed using a plurality of data to create new data.
As shown in this figure, the primary user 4 extracts the parts M4, M5, M6 that make up the data from multiple original data M1, M2, M3 obtained from a single database or from multiple databases. Then, these parts M4, M5, M6 are used to generate new data M7.
The primary user 4 supplies the new data M7 generated in this way to the secondary user 5, but the new data M7 is a secondary generated by the primary user 4 processing the original data M1, M2, M3. In addition to the original copyright, there is also the original copyright for the original data M1, M2, M3 from which the parts M4, M5, M6, which are the raw materials for generating the data M7, are obtained.
Each of these original data M1, M2, M3 is encrypted with the second private key Ks2 supplied with each data when it is used for purposes other than display, that is, when it is stored, processed, copied or transferred, but Cm1ks2 = E (Ks2). , M1) Cm2ks2 = E (Ks2, M2) Cm3ks2 = E (Ks2, M3) Parts M4, M5, M6 of each original data are also the second secret supplied with each data when it is used for purposes other than display. Encrypted with key Ks2. Cm4ks2 = E (Ks2, M4) Cm5ks2 = E (Ks2, M5) Cm6ks2 = E (Ks2, M6)
The new data consists of the original data and the act of processing the data.
In computer technology, data processing is represented by the original data and its processing process. Then, this original data and the processing process can be expressed as a computer program and data described in the computer program. Such an integration of program and data is called an object, and it is called an object-oriented technology that performs processing on a computer on an object-by-object basis, and has become the mainstream technology in recent computer technology. ing.
The technology for creating new data from multiple data is called a framework or scenario, and typical ones are Microsoft's "OLE" (Object Linking and Embedding) and Apple's "OpenDoc".
In the present invention, the relationship between the original data and the framework or scenario that is the processing process are treated as an object together with the original data.
The primary user 4 who is a data processor digitally signs the processing program Pe using the first dedicated key Kv1, and Spe = D (Kv1, Pe) along with the digitally signed processing program Pe, the original encrypted data component Cm4ks2, Supply Cm5ks2 and Cm6ks2 to the secondary user 5.
Secondary user 5 who receives the encrypted original data parts Cm4ks2, Cm5ks2, Cm6ks2 together with the digitally signed processing program Pe presents the digitally signed processing program Pe to the copyright management center 8 and encrypts it. Request the second private key Ks2 to decrypt the original data components Cm4ks2, Cm5ks2, Cm6ks2.
The copyright management center 8 confirms the primary user 4 from the digital signature of the processing program Pe presented using the first public key Kb1, and Pe = E (Kb1, Spe), and the primary user 4 is the second secret. Confirm that the key Ks2 is a legitimate user of the requested original data, and if the primary user 4 is a legitimate user, transfer the second private key Ks2 to the secondary user 5. However, if the primary user 4 is not a legitimate user, the second private key Ks2 is not transferred to the secondary user 5.
The digital signature Spe presented to the copyright management center 8 is registered with the copyright management center 8 as a formal procedure for proving that the copyright holder is a secondary copyright holder.
In addition, the primary use to the nth use do not continue forever, but the order is limited to an appropriate order according to the operational judgment of the database side or the original copyright holder, and it is forcibly registered in the database as the original work. May be good.
Another embodiment will be described with reference to FIG.
In this system, the primary usage key K1 including the first private key Ks1, the secondary usage key K2 including the second private key Ks2, the third private key Ks2, the original copyright label Lc1 in plain text, and the copyright in plain text. A management program PC is used.
The data copyright management system shown in FIG. 3 consists of a database 11, a key management center 12, users 13, 13, 13 ... And a network 14 that connects them to each other. In addition, data is supplied to database 11 from information providers (IP) 15,15,15 ..., but in some cases, information providers 16,16,16, etc. do not go through database 11. -Data may be supplied directly to user 13 via network 14.
The data used in the present invention is an object in which a program and data are combined.
In addition, data is supplied to the primary user 13 from the information providers 15, 15, 15 ... To the database 11, but in some cases, the information providers 16, 16, 16 ... Via the network 14. Alternatively, data may be directly supplied to the primary user 13 via an information recording medium 17 such as a CDROM without going through the database 11.
In this figure, the solid line shows the plaintext data and the encryption key request route, the broken line shows the encrypted data route, and the alternate long and short dash line shows the encryption key route.
The primary user 13 can be an informant 15 or 16 that provides a new work (derivative work) by combining or modifying a plurality of obtained original data, not just a user.
In the data copyright management system of the present invention configured in this way, the original data provided by each of the information providers 15 and 16 is encrypted in order to protect the copyright. Therefore, in order to use the encryption source data obtained by the user 13, the encryption source data must be decrypted. In this system, all the encryption keys for that purpose are deposited in the key management center 12 and managed by the key management center 12.
In addition, the encryption method adopted by each information provider 15 and 16 is free, but the encryption method used after the secondary use described later is limited to the method adopted by the key management center 12.
Data from a database is generally used using a personal computer, but it is necessary to use an OS that incorporates security-related processing as the OS used there. In addition, a copyright management program is used to manage encryption keys, etc., but since it is necessary to store the encryption key received from this copyright management program and the key management center 12, it is stored in memory as software. Alternatively, a "key card" realized on the HDD or a "key card" realized as hardware by a dedicated board, PC card, etc. is prepared as a storage place for these.
The Key Management Center 12 uses an encryption key to protect the copyright of data works and to charge for the use of copyright, regardless of whether they are actually used or simply registered and not used. The encryption key is managed by storing and associating the stored encryption key with the copyright label.
In this system, the plaintext original data M0 is encrypted using the first private key Ks1 and is connected to network 14 from information provider 15 via database 11 with Cm0ks1 = E (Ks1, M0) original copyright label Lc1. It is supplied from the information provider 16 to the primary user 13 via the network 14 or via an information recording medium 17 such as a CDROM.
The plaintext original copyright label Lc0 is attached to the encrypted original data Cm0ks1 supplied to the primary user 13, and the plaintext original copyright label Lc0 is used for obtaining the primary usage key. That is, the original encryption data Cm0ks1 is composed of the plaintext original copyright label Lc0 and the original encryption data Cm0ks1. In the plaintext original copyright label Lc0, in addition to general information such as the original author name, title name, production date, etc. of the original data, the application program name used, outline explanation, usage fee, billing method, etc. are described. In addition, the number of the usage key is described if necessary. If the plaintext original copyright label Lc0 is digitally signed by the original copyright holder, false declarations can be prevented.
The primary user 13 who wishes to use the supplied encrypted original data Cm0ks1 presents the original copyright label Lc1 to the key management center 12 via the network 14 and requests the distribution of the primary usage key K1.
Based on the presented primary copyright label Lc1, the key management center 12 confirms that the primary usage key to be distributed is the key K1. The confirmed primary usage key K1 is passed through the network system 14 to the primary usage key K1. Distribute to user 13. When the distributed primary usage key K1 is received, the device of the primary user 13 enters the copyright management mode, and the primary user 13 can use the primary copyright data. Since the first private key Ks1 is included in the primary usage key K1, it is not recognized by the primary user 13.
On the other hand, the key management center 12 performs billing processing and grasps the usage status of copyright data and the database usage status of the primary user 13.
The primary user 13 decrypts the encrypted primary copyright data Cm0ks1 using the primary private key Ks1 included in the distributed primary usage key K1 and uses M0 = D (Ks1, Cm0ks1).
When the decrypted original data M0 is saved in the device of the primary user 13, it is re-encrypted using the first private key Ks1 and the Cm0ks1 = E (Ks1, M0) encrypted original data Cm0ks1 is saved. To.
When reusing the re-encrypted original data Cm0ks1, re-decryption and re-encryption are performed using the first private key Ks1.
The primary user 13 who wishes to process the original copyright data M0 requests the key management center 12 to distribute the secondary usage key K2 via the network 14.
Upon receiving the request for distribution of the secondary usage key K2, the key management center 12 distributes the secondary usage key K2 to the primary user 13 via the network 14.
The primary user 13 who receives the secondary usage key K2 processes the original data M0 and obtains the intermediate processing data M0'.
When the intermediate processing data M0'is stored in the device of the user 13, it is encrypted by the second private key Ks2. Cm0'ks2 = E (Ks2, M0')
When the processing is finally completed, the primary user 13 prepares the third private key Ks3 to exercise the secondary copyright related to the data processing of the final processing data M1, and the third private key Ks3 is used as the key management center 12 Register with. The third private key Ks3 may be prepared by the key management center 12 instead of the primary user 13 and distributed at the request of the primary user 13.
When the primary user 13 copies the processed data M1 to the external storage medium 18 or transfers it via the network 14, it is encrypted using the third private key Ks3, and Cm1ks3 = E (Ks3, M1) secondary user. Supply to 19.
The secondary user 19 who wishes to use the supplied encrypted data Cm1ks3 requests the key management center 12 to distribute the third private key Ks3 via the network 14.
Upon receiving the distribution request of the third private key Ks3 from the secondary user 19, the key management center 12 distributes the third private key Ks3 to the secondary user 19 via the network 14.
The secondary user 19 who receives the third private key Ks3 decrypts the encrypted data Cm1ks3 using the third private key Ks3 and uses M1 = D (Ks3, Cm1ks3).
Even in that case, when the encrypted data Cm1ks3 is reused, the encryption and encryption are performed using the third private key Ks3.
Explain the restrictions on primary use imposed by the copyright management program Pc.
Similar to the invention described in Japanese Patent Application No. 6-64889, which is a prior application, the use of the data obtained and decrypted in the data copyright management system of the present invention is a normal usage pattern, that is, direct use of the data. It is limited to output including printing of the results of use and its use, and cannot be copied to an external storage medium, transferred and processed via a network system, and in principle, data cannot be stored inside the device. It is possible to save the encrypted data.
Needless to say, it is possible to display, print, save, copy, process, and transfer non-copyrighted data by the application program in use.
The encrypted original data Cm0ks1 obtained by the primary user 13 from an external informant 15 or 16 directly or through the database 11 is combined with the original copyright label Lc0 supplied together with the terminal of the primary user 13. It is stored in a hard disk drive in the device or a storage device that is a non-volatile memory.
The primary user 13 who wishes to use the encrypted original data Cm0ks1 stored in the storage device for the first time refers to the plaintext original copyright label Lc1 and uses the environment of the application program etc. used by the original data M0. To confirm.
As a result, it is determined that the original data M0 can be used, and when the primary user 13 informs the copyright management program Pc that the original data M0 is used, the copyright management program Pc tells the copyright management program Pc that the original data M0 is used. Start the application program you are using, and the encrypted source data Cm0ks1 is read from the storage device into the volatile memory inside the device.
On the other hand, when the primary copyright label Lc1 is sent to the key management center 12, and as a result, the primary usage key K1 is supplied according to the processing flow described above, the encryption source data Cm0ks1 becomes the primary usage key. It is decrypted using the first private key Ks1 included in K1 and can be used by the application program started with M0 = D (Ks1, Cm0ks1).
When saving the decrypted original data M0 on the volatile memory of the terminal device of the primary user 13 in the storage device, encrypt it using the first private key Ks1 and save it as Cm0ks1 = D (Ks1, M0). Is done.
This saving also includes the creation and saving of a temporary file (Temporaly File) for data preservation.
When reusing the re-encrypted data Cm0ks1, re-decryption and re-encryption are performed using the first private key Ks1.
If the primary usage key K1 is used, the copyright management program Pc can be used to display / print the decryption source data M0 and save the encryption source data Cm0ks1, but other usage patterns. That is, storage, processing, copying to an external storage medium, transfer to another device, copying of the encrypted source data Cm0ks1 to an external storage medium, and transfer to another device are prohibited.
Therefore, it is also prohibited by the copyright management program Pc to cut out a part of the original data M0 and paste it on another general data D (Cut & Paste) and to cut out a part of the general data D and paste it on the original data M0. Will be done.
In addition, the original data M0 can be exceptionally stored in the storage device if it is encrypted using the first private key Ks1, but storage is prohibited if any processing is performed.
The copyright management program Pc determines the distinction between the original data M0 for which the copyright is claimed and the general data D for which the copyright is not claimed, and whether or not the original data M0 has been processed.
This determination is made by examining the management table that describes the attributes of the files that make up the computer file together with the file itself. In this management table, in addition to the file size and creation date, a flag indicating that a copyright claim has been made is entered, and by examining these, whether or not a copyright claim has been made and whether the file has been processed can be determined. Whether or not it was done is determined.
The original data M0 is combined with the original copyright label Lc1 as the encrypted original data Cm0ks1 when stored in the storage device, but when it is decrypted and read into the volatile memory, it is decrypted by the copyright management program Pc. The original data M0 and the original copyright label Lc1 are separated, and the separated copyright label Lc1 is managed by the copyright management program Pc.
The copyright management program Pc monitors which application program the original data M0 is used by, and cuts / pastes the original data M0 to the general data D and cuts / pastes the general data D to the original data M0. Prohibit being struck.
Explain the restrictions on data processing performed by the copyright management program Pc.
As a result of the primary use, the primary user 13 who decides to process the original data M0 notifies the key management center 12 via the network 14 that the original data M0 will be processed, and the original data M0 is processed. Request the key management center 12 to distribute the secondary use key K2 for processing.
Upon receiving the request for distribution of the secondary usage key K2, the key management center 12 distributes the secondary usage key K2 to the primary user 13 via the network system 14.
As a result, the terminal device of the primary user 13 is put into the processing mode, and the original data M0 can be processed by the primary user 13.
The primary user 13 decrypts the encrypted original data Cm0ks1 using the first private key Ks1 and then displays it on the display device to process the data. First, the original data M0 is protected in order to protect the original data M0. Is copied, and the processing original data M0'obtained by this copying is processed.
When saving the original data M0'for processing or the data M0' in the process of processing in the storage device in the terminal device of the primary user 13, the second private key Ks2 included in the secondary usage key K2 is used. Is encrypted and saved as Cm0'ks2 = E (Ks2, M0') or Cm0 "ks2 = E (Ks2, M0").
Since the encrypted original data M0 is stored in the storage device without being processed, the file can be obtained by checking the file size and creation date of the management table and the data M0 "in the process of processing or the processed data M1. It is possible to determine whether or not the file is a processed file.
Multiple primary processing data M11, M12, M13 ... are generated by data processing, but the secondary copyright of the primary user 13 is generated in these primary processing data M11, M12, M13 ... To do. Note that these primary processed data M11, M12, M13 ... are plaintext when they are on the volatile memory of the primary user terminal device, but are encrypted using the second private key Ks2 when stored in the storage device. Cm11ks2 = E (Ks2, M11) Cm12ks2 = E (Ks2, M12) Cm13ks2 = E (Ks2, M13)
In order to exercise the secondary copyright for these primary processing data M11, M12, M13 ..., the primary user 13 distributes the third private key Ks3 to the key management center 12 via the network 14. Upon request, the key management center 12 distributes the third private key Ks3 to the primary user 13 in response to this distribution request.
The primary user 13 who received the distribution of the third private key Ks3 encrypts the plaintext or decrypted primary processed data M11, M12, M13 ... Using the third private key Ks3, and Cm11ks3 = E (Ks3). , M11) Cm12ks3 = E (Ks3, M12) Cm13ks3 = E (Ks3, M13) Encrypted primary processing data Cm11ks3, Cm12ks3, Cm13ks3 ... is saved in the storage device in the primary user terminal device. To.
When using this encrypted data Cm11ks3, Cm12ks3, Cm13ks3 ..., Decryption and encryption are performed using the third private key Ks3.
The primary processing data M11, M12, M13 ... Processed by the primary user 13 includes the primary copyright of the original data M0 before processing owned by the information provider, as well as the primary copyright for data processing. Derivative copyright of user 13 exists. In order to exercise this secondary copyright, the primary user 13 sends the key management center 12 together with the third private key Ks3, the title name of the data, the name of the application program used, the content summary, and the name of the primary copyright holder. Is sent, and the key management center 12 stores and manages it together with the third private key Ks3.
On the other hand, the primary user 13 supplies the encrypted primary processed data Cm11ks3, Cm12ks3, Cm13ks3 ... To the secondary user 19 by copying or transferring the encrypted primary processing data to the external storage medium 18 via the network 14.
The secondary user 19 who wishes to use the supplied encrypted primary processing data Cm11ks3, Cm12ks3, Cm13ks3 ... requests the key management center 12 to distribute the third usage permission key K3 including the third private key Ks3. To do. The use of the primary processing data M11, M12, M13 ... By this third usage permission key K3 is limited to general use such as display and printing and storage in the storage device in the user terminal device, and is primary. Processing data M11, M12, M13 ... or encrypted primary processing data Cm11ks3, Cm12ks3, Cm13ks3 ... Copy to external storage medium 18 or transferred to a tertiary user via network 14 and primary processing Data M11, M12, M13 ... cannot be reprocessed.
As described above, the copyright data handled in the present invention is intended for an "object" in which a program and data are integrated, and this object can be handled as a component in computer programming or various processes.
A case of creating new processing data using a plurality of original data which are objects will be described with reference to FIGS. 4 and 3.
In Fig. 4, 31, 32, 33 are the original data M31, M32, M33 with copyright claims configured as objects, respectively, and the new primary processing data M3030 using these original data M31, M32, M33. Is created.
As the processing form of the original data M31, M32, M33, all of them are used like the primary processing data M34 shown in 34, and a part of them is used like the primary processing data M35 shown in 35. There are three forms of using it, or modifying it like the primary processing data M36 shown in 36.
The processing of the original data is performed by linking and quoting the copyright data for each object and superimposing / combining them, and such superimposition and combination can be freely performed.
In addition, other items can be added to the primary processing data M3737 that has been superposed / combined in this way.
The primary processing data M3030 newly created in this way is configured as an aggregate of objects.
As mentioned earlier, in addition to the copyright of the original data M31, M32, and M33, the primary processing data M30 created in this way newly has the secondary copyright of the primary user 13 regarding processing. To do.
In order to exercise the secondary copyright of the primary user 13, it is necessary to encrypt the primary processed data, and therefore the primary user 13 corresponds to the respective primary processed data M34, M35, M36. 3 Prepare the private keys Ks34, Ks34, Ks36, encrypt the plaintext primary processing data M34, M35, M36 using the corresponding third private keys Ks34, Ks34, Ks36, and Cm34ks34 = E (Ks34, M34). ) Cm35ks35 = E (Ks35, M35) Cm36ks36 = E (Ks36, M36) Supply to the secondary user 19 by copying to the external storage medium 18 or transferring via the network 14.
In addition, the third private keys Ks34, Ks34, and Ks36 are registered in the key management center 12. By registering the third private key, the secondary copyright of the primary user 13 is registered in the key management center 12.
At this time, the primary user 13 sends to the key management center 12 the third private key in addition to the plurality of third private keys Ks34, Ks35, Ks36 corresponding to the number of the created plurality of primary processing data. Number of, 2nd private keys Ks24, Ks25, Ks26, original data name, information of other original data linked, access path to the original data used, application used by the original data M11, M12, M13 Explanation of the program and the outline of the work.
The key management center 12 that received a plurality of third private keys Ks34, Ks35, Ks36 has the original data name, information on other linked original data, access path to the original data used, original data M11, M12. Prepare copyright labels Lc34, Lc35, and Lc36 corresponding to multiple primary processing data by using the application program used by M13 and the outline explanation of the work.
At this time, the link between the newly created primary processing data M34, M35, M36 and the original data M11, M12, M13 is released. At the time of breaking the link, the substance of the original data that had only a link relationship with the primary machining data M34, M35, M36 until then became the newly created primary machining data M34, M35, M36. This makes it possible to exercise the secondary copyright of the encrypted primary processing data Cm34ks34, Cm35ks35, and Cm36ks36 supplied to the secondary user 19.
The secondary user 19 who wishes to use the supplied encrypted primary processing data, for example, M34, requests the key management center 12 to distribute the third private key Ks34.
Upon receiving the distribution request for the third private key Ks34, the key management center 12 distributes the third private key Ks34 to the secondary user 19 via the network 14.
The secondary user 19 who receives the third private key Ks3 decrypts the encrypted primary processing data Cm34ks34 using the third private key Ks34 and uses M34 = E (Ks34, Cm34ks34).
The copyright holder of the original data or the copyright holder of the primary processed data can change the access path by applying to the key management center 12.
In addition, the copyright holder of the original data or the copyright holder of the primary processed data can process (correct) the data using the third private key, and can also use another key. Is.
<figref num="1">The block diagram of the database copyright management system of an Example of this invention.</figref><figref num="2">An explanatory diagram for creating new copyright data using multiple copyright data that are objects.</figref><figref num="3">Schematic block diagram of another embodiment of the data copyright processing system of the present invention.</figref><figref num="4">An explanatory diagram for creating new copyright data using multiple copyright data that are objects.</figref>
Code description
1,2,3 Database 8 Copyright Management Center 4,5,6,7 User 9 Communication Line 15,16 Information Provider 17 Information Recording Media 18 External Storage Media 19 Secondary User
Every citation, both waysCites: the store holds 5 of 6
| Document | Relation | Office |
|---|---|---|
| JP08329011A | Cites | Japan |
| JP07302244A | Cites | Japan |
| JP04181282A | Cites | Japan |
| JP08292976A | Cites | Japan |
| JP10512074A | Cites | Japan |
123 members in 4 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 1994264201 | Japan | – | |
| 26420194 | Japan | A | |
| 26420194 | Japan | A | |
| 2005298846 | Japan | A | |
| 1994264201 | – | – | – |
| JP19940264201 | – | – | – |
| JP20050298846 | – | – | – |
Members123
| Document | Office | Kind | |
|---|---|---|---|
| EP0677949A2 | European Patent Office (EPO) | A2 | |
| JPH07271865A | Japan | A | |
| EP0677949A3 | European Patent Office (EPO) | A3 | |
| EP0704785A2 | European Patent Office (EPO) | A2 | |
| EP0709760A2 | European Patent Office (EPO) | A2 | |
| EP0715241A2 | European Patent Office (EPO) | A2 | |
| EP0719045A2 | European Patent Office (EPO) | A2 | |
| JPH08185448A | Japan | A | |
| EP0719045A3 | European Patent Office (EPO) | A3 | |
| JPH08272745A | Japan | A | |
| JPH08287014A | Japan | A | |
| JPH08288940A | Japan | A | |
| US5646999A | United States of America | A | |
| US5740246A | United States of America | A | |
| US5867579A | United States of America | A | |
| EP0709760A3 | European Patent Office (EPO) | A3 | |
| EP0715241A3 | European Patent Office (EPO) | A3 | |
| EP0704785A3 | European Patent Office (EPO) | A3 | |
| US5974141A | United States of America | A | |
| US6002772A | United States of America | A | |
| US6069952A | United States of America | A | |
| US6076077A | United States of America | A | |
| US6097818A | United States of America | A | |
| US6128605A | United States of America | A | |
| US6182218B1 | United States of America | B1 | |
| US6272635B1 | United States of America | B1 | |
| US2001013021A1 | United States of America | A1 | |
| EP1133163A2 | European Patent Office (EPO) | A2 | |
| US2001027522A1 | United States of America | A1 | |
| EP1133163A3 | European Patent Office (EPO) | A3 | |
| US2002021807A1 | United States of America | A1 | |
| US2002025044A1 | United States of America | A1 | |
| US2002052850A1 | United States of America | A1 | |
| US2002059238A1 | United States of America | A1 | |
| US6408390B1 | United States of America | B1 | |
| US6424715B1 | United States of America | B1 | |
| US2002112173A1 | United States of America | A1 | |
| US6438694B2 | United States of America | B2 | |
| US6449717B1 | United States of America | B1 | |
| US6463536B2 | United States of America | B2 | |
| US2002178372A1 | United States of America | A1 | |
| US2003012385A1 | United States of America | A1 | |
| EP0677949B1 | European Patent Office (EPO) | B1 | |
| DE69530888D1 | Germany | D1 | |
| US2003144963A1 | United States of America | A1 | |
| JP2003242286A | Japan | A | |
| JP2003250136A | Japan | A | |
| EP0719045B1 | European Patent Office (EPO) | B1 | |
| EP0704785B1 | European Patent Office (EPO) | B1 | |
| DE69532028D1 | Germany | D1 | |
| DE69532153D1 | Germany | D1 | |
| EP0715241B1 | European Patent Office (EPO) | B1 | |
| DE69532434D1 | Germany | D1 | |
| JP2004072792A | Japan | A | |
| US6721887B2 | United States of America | B2 | |
| DE69530888T2 | Germany | T2 | |
| US6741991B2 | United States of America | B2 | |
| US6744894B1 | United States of America | B1 | |
| DE69532028T2 | Germany | T2 | |
| DE69532153T2 | Germany | T2 | |
| US6789197B1 | United States of America | B1 | |
| JP2004303265A | Japan | A | |
| DE69532434T2 | Germany | T2 | |
| US2005262023A1 | United States of America | A1 | |
| JP2006085725A | Japan | A | |
| US7036019B1 | United States of America | B1 | |
| EP0709760B1 | European Patent Office (EPO) | B1 | |
| DE69535013D1 | Germany | D1 | |
| JP2006180562A | Japan | A | |
| EP1133163B1 | European Patent Office (EPO) | B1 | |
| EP1691315A1 | European Patent Office (EPO) | A1 | |
| EP1691316A1 | European Patent Office (EPO) | A1 | |
| DE69535161D1 | Germany | D1 | |
| EP1710997A2 | European Patent Office (EPO) | A2 | |
| EP1722548A2 | European Patent Office (EPO) | A2 | |
| JP3850058B2 | Japan | B2 | |
| JP2006325246A | Japan | A | |
| US2006282674A1 | United States of America | A1 | |
| DE69535013T2 | Germany | T2 | |
| US2007033143A1 | United States of America | A1 | |
| US2007038575A1 | United States of America | A1 | |
| US2007061267A1 | United States of America | A1 | |
| US2007079145A1 | United States of America | A1 | |
| US2007088960A1 | United States of America | A1 | |
| EP1710997A3 | European Patent Office (EPO) | A3 | |
| EP1722548A3 | European Patent Office (EPO) | A3 | |
| US2007110228A1 | United States of America | A1 | |
| DE69535161T2 | Germany | T2 | |
| US7302415B1 | United States of America | B1 | |
| JP4030486B2 | Japan | B2 | |
| JP2008090849A | Japan | A | |
| US7383447B2 | United States of America | B2 | |
| JP4099461B2 | Japan | B2 | |
| JP4101263B2This record | Japan | B2 | |
| US7447914B1 | United States of America | B1 | |
| EP1722548B1 | European Patent Office (EPO) | B1 | |
| DE69535956D1 | Germany | D1 | |
| JP4386898B2 | Japan | B2 | |
| JP4431306B2 | Japan | B2 | |
| JP2010063130A | Japan | A |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: R3D02RD02 | RD02 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 4101263
- Publication, DOCDB
- 4101263
- Publication, EPODOC
- JP4101263B
- Application
- 298846
- Application, DOCDB
- 2005298846
- Application, EPODOC
- JP20050298846
Titles2
- English
- Data copyright management system
- Japanese
- データ著作権管理システム
Classification
- CPC, 20
- H04L9/083
- G06F21/10
- G06F2211/007
- G06F2211/008
- G06F2221/2101
- G06F2221/2117
- H04L9/0825
- H04L9/3247
- H04L63/0428
- H04L63/0442
- H04L63/0464
- H04L63/061
- H04L63/12
- H04L63/126
- H04L2209/605
- H04L2463/101
- H04N5/913
- H04N7/162
- H04N21/63345
- H04N2005/91364
- IPC, 14
- G06F21 24
- H04L9 08
- H04L9 32
- G06F21 00
- G06F1 00
- G06F15 00
- G06F21 10
- G06F21 62
- G09C1 00
- H04L9 30
- H04L29 06
- H04N1 44
- H04N5 913
- H04N7 16