Data protection system for protecting data through encryption
Abstract
This record has no abstract on file.
Term
Term ended
Expired 27 March 2022, 4.5 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
5 claims: 5 independent, 0 dependent
- 1A decryption terminal for acquiring and decrypting encrypted data, which stores the decryption key group individually assigned by a predetermined key allocation method, and the decryption key group storage means, and the encrypted data. An encrypted data acquisition means to be acquired, and a decryption means for decrypting the data acquired by the encrypted data acquisition means by using a decryption key stored in the decryption key group storage means.With, The predetermined key allocation method is as follows:(a) A set of a plurality of terminals in which the terminal is a set including two or more terminals in the case of assuming three or more terminals including the terminal.At least one ofFurther, it is a plurality of terminal sets each including the terminal as an element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are multiple terminal sets where the relationship is establishedFurther, there is a terminal set that completely includes the plurality of terminal sets, and a plurality of terminal sets that each include the same one or more terminal sets, and any one of the plurality of terminal sets. So that there is a plurality of terminal sets in which the relation that the terminal set of is not a subset of each other terminal set in the plurality of terminal sets is established.MultipleDetermine the terminal set of, (b) determine a separate decryption key for this terminal and for each determined terminal set, and (c) determine for this terminal corresponding to this terminal. A decryption terminal, which is a method of allocating a decryption key group based on a decryption key and a decryption key determined corresponding to each of all terminal sets including this terminal. 暗号化されたデータを取得して復号するための復号端末であって、 所定鍵割当方法により個別に割当てられた復号鍵群を記憶している復号鍵群記憶手段と、 暗号化されたデータを取得する暗号化データ取得手段と、 前記暗号化データ取得手段により取得されたデータを、前記復号鍵群記憶手段に記憶されている復号鍵を用いて復号する復号手段とを備え、 前記所定鍵割当方法は、 (a) 本端末を含む3台以上の端末を想定した場合において本端末が、2つ以上の端末を要素に含む集合である複数の端末集合の少なくとも1つに属するように、 更に、本端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、更に、前記複数の端末集合を完全に包含する端末集合が存在するように、かつ、同じ1つ以上の端末集合を各々包含する複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、複数の端末集合を決定し、 (b) 本端末に対応して及び決定した端末集合毎に対応して各々別個の復号鍵を定め、 (c) 本端末に対して、本端末に対応して定めた復号鍵、及び本端末を含む全ての端末集合の各々に対応して定めた復号鍵に基づいて、復号鍵群を割り当てる方法である ことを特徴とする復号端末。
- 2The predetermined key allocation method is a method of assigning the decryption key determined corresponding to the terminal and the decryption key determined corresponding to each of all the terminal sets including the terminal to the terminal. A claim characterized by1The decryption terminal described. 前記所定鍵割当方法は、 本端末に対して、本端末に対応して定めた復号鍵、及び本端末を含む全ての端末集合の各々に対応して定めた復号鍵を全て割り当てる方法である ことを特徴とする請求項1記載の復号端末。
- 3A decryption method for acquiring and decrypting encrypted data. A decryption key group storage step of storing a decryption key group individually assigned by a predetermined key allocation method in the decryption key group storage unit of the decryption terminal, and a decryption key group storage step. An encrypted data acquisition step in which the acquisition unit of the decryption terminal acquires the encrypted data, The decoding unit of the decoding terminal includes a decoding step of decoding the data acquired by the acquisition unit using the decoding key stored in the decoding key group storage unit. The predetermined key allocation method is(a) Assuming three or more terminals including the decoding terminal, the decoding terminal belongs to at least one of a plurality of terminal sets which are a set including two or more terminals as elements. Further, a relationship is established in which there are a plurality of terminal sets each including the decoding terminal as an element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are such multiple terminal setsFurther, there is a terminal set that completely includes the plurality of terminal sets, and a plurality of terminal sets that each include the same one or more terminal sets, and any one of the plurality of terminal sets. So that there is a plurality of terminal sets in which the relation that the terminal set of is not a subset of each other terminal set in the plurality of terminal sets is established. Determine multiple terminal sets and(b) A separate decryption key is determined for each of the decryption terminals and for each determined terminal set.(c) For the decryption terminal, the decryption key determined corresponding to the decryption terminal and the decryption terminalThis is a method of assigning a decryption key group based on a decryption key determined corresponding to each of all terminal sets including. A decoding method characterized by that. 暗号化されたデータを取得して復号するための復号方法であって、 復号端末の復号鍵群格納部に、所定鍵割当方法により個別に割当てられた復号鍵群を記憶させる復号鍵群記憶ステップと、 前記復号端末の取得部が、暗号化されたデータを取得する暗号化データ取得ステップと、 前記復号端末の復号部が、前記取得部により取得されたデータを、前記復号鍵群格納部に記憶されている復号鍵を用いて復号する復号ステップとを含み、 前記所定鍵割当方法は、(a) 前記復号端末を含む3台以上の端末を想定した場合において前記復号端末が、2つ以上の端末を要素に含む集合である複数の端末集合の少なくとも1つに属するように、 更に、前記復号端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、更に、前記複数の端末集合を完全に包含する端末集合が存在するように、かつ、同じ1つ以上の端末集合を各々包含する複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 複数の端末集合を決定し、(b) 前記復号端末に対応して及び決定した端末集合毎に対応して各々別個の復号鍵を定め、(c) 前記復号端末に対して、当該復号端末に対応して定めた復号鍵、及び当該復号端末を含む全ての端末集合の各々に対応して定めた復号鍵に基づいて、復号鍵群を割り当てる方法である ことを特徴とする復号方法。
- 4A decryption program for causing a computer functioning as a decryption terminal having a decryption key storage unit, an acquisition unit, and a decryption unit to execute a process of acquiring and decrypting encrypted data. A decryption key group storage step of storing a decryption key group individually assigned by a predetermined key allocation method in the decryption key group storage unit, and a decryption key group storage step. An encrypted data acquisition step of causing the acquisition unit to acquire encrypted data, The decoding unit includes a decoding step of decoding the data acquired by the acquisition unit using the decoding key stored in the decoding key group storage unit. The predetermined key allocation method is(a) Assuming three or more terminals including the decoding terminal, the decoding terminal belongs to at least one of a plurality of terminal sets which are a set including two or more terminals as elements. Further, a relationship is established in which there are a plurality of terminal sets each including the decoding terminal as an element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are such multiple terminal setsFurther, there is a terminal set that completely includes the plurality of terminal sets, and a plurality of terminal sets that each include the same one or more terminal sets, and any one of the plurality of terminal sets. So that there is a plurality of terminal sets in which the relation that the terminal set of is not a subset of each other terminal set in the plurality of terminal sets is established. Determine multiple terminal sets and(b) A separate decryption key is determined for each of the decryption terminals and for each determined terminal set.(c) A method of assigning a decryption key group to the decryption terminal based on the decryption key determined corresponding to the decryption terminal and the decryption key determined corresponding to each of all the terminal sets including the decryption terminal. is there A decryption program characterized by that. 暗号化されたデータを取得して復号する処理を、復号鍵格納部と取得部と復号部とを備える復号端末として機能するコンピュータに実行させるための復号プログラムであって、 前記復号鍵群格納部に、所定鍵割当方法により個別に割当てられた復号鍵群を記憶させる復号鍵群記憶ステップと、 前記取得部に、暗号化されたデータを取得させる暗号化データ取得ステップと、 前記復号部に、前記取得部により取得されたデータを、前記復号鍵群格納部に記憶されている復号鍵を用いて復号させる復号ステップとを含み、 前記所定鍵割当方法は、(a) 前記復号端末を含む3台以上の端末を想定した場合において前記復号端末が、2つ以上の端末を要素に含む集合である複数の端末集合の少なくとも1つに属するように、 更に、前記復号端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、更に、前記複数の端末集合を完全に包含する端末集合が存在するように、かつ、同じ1つ以上の端末集合を各々包含する複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 複数の端末集合を決定し、(b) 前記復号端末に対応して及び決定した端末集合毎に対応して各々別個の復号鍵を定め、(c) 前記復号端末に対して、当該復号端末に対応して定めた復号鍵、及び当該復号端末を含む全ての端末集合の各々に対応して定めた復号鍵に基づいて、復号鍵群を割り当てる方法である ことを特徴とする復号プログラム。
- 5A recording medium on which a decryption program is recorded for executing a process of acquiring and decrypting encrypted data by a computer functioning as a decryption terminal including a decryption key storage unit, an acquisition unit, and a decryption unit. A decryption key group storage step of storing a decryption key group individually assigned by a predetermined key allocation method in the decryption key group storage unit, and a decryption key group storage step. An encrypted data acquisition step of causing the acquisition unit to acquire encrypted data, The decoding unit includes a decoding step of decoding the data acquired by the acquisition unit using the decoding key stored in the decoding key group storage unit. The predetermined key allocation method is(a) Assuming three or more terminals including the decoding terminal, the decoding terminal belongs to at least one of a plurality of terminal sets which are a set including two or more terminals as elements. Further, a relationship is established in which there are a plurality of terminal sets each including the decoding terminal as an element, and none of the terminal sets in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. So that there are such multiple terminal setsFurther, there is a terminal set that completely includes the plurality of terminal sets, and a plurality of terminal sets that each include the same one or more terminal sets, and any one of the plurality of terminal sets. So that there is a plurality of terminal sets in which the relation that the terminal set of is not a subset of each other terminal set in the plurality of terminal sets is established. Determine multiple terminal sets and(b) A separate decryption key is determined for each of the decryption terminals and for each determined terminal set.(c) A method of assigning a decryption key group to the decryption terminal based on the decryption key determined corresponding to the decryption terminal and the decryption key determined corresponding to each of all the terminal sets including the decryption terminal. is there A recording medium characterized by that. 暗号化されたデータを取得して復号する処理を、復号鍵格納部と取得部と復号部とを備える復号端末として機能するコンピュータに実行させるための復号プログラムを記録した記録媒体であって、 前記復号鍵群格納部に、所定鍵割当方法により個別に割当てられた復号鍵群を記憶させる復号鍵群記憶ステップと、 前記取得部に、暗号化されたデータを取得させる暗号化データ取得ステップと、 前記復号部に、前記取得部により取得されたデータを、前記復号鍵群格納部に記憶されている復号鍵を用いて復号させる復号ステップとを含み、 前記所定鍵割当方法は、(a) 前記復号端末を含む3台以上の端末を想定した場合において前記復号端末が、2つ以上の端末を要素に含む集合である複数の端末集合の少なくとも1つに属するように、 更に、前記復号端末を各々要素に含む複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、更に、前記複数の端末集合を完全に包含する端末集合が存在するように、かつ、同じ1つ以上の端末集合を各々包含する複数の端末集合であって、当該複数の端末集合におけるいずれの一の端末集合も当該複数の端末集合における他の各端末集合の部分集合でないという関係が成立するところの当該複数の端末集合が存在するように、 複数の端末集合を決定し、(b) 前記復号端末に対応して及び決定した端末集合毎に対応して各々別個の復号鍵を定め、(c) 前記復号端末に対して、当該復号端末に対応して定めた復号鍵、及び当該復号端末を含む全ての端末集合の各々に対応して定めた復号鍵に基づいて、復号鍵群を割り当てる方法である ことを特徴とする記録媒体。
Independent claims5
187 paragraphs, as filed
The present invention relates to a data protection system that encrypts and distributes data to a plurality of terminals, and more particularly to a technique for determining a key used for data encryption and decryption.
PROBLEM TO BE SOLVED: To generate digital contents composed of moving images, audio and the like and store them in a large-capacity recording medium such as an optical disk against the background of recent development of multimedia-related technology and the emergence of a large-capacity recording medium. A system to distribute is appearing. The digital contents recorded on the distributed optical discs and the like are read out by terminals such as computers and playback devices, and are subject to reproduction, copying, and the like.
[0003] In such a system, an encryption technique is generally used in order to protect the so-called copyright of the digital content, that is, to prevent unauthorized use such as unauthorized copying of the digital content. That is, such a system encrypts digital contents using a certain encryption key, records them on an optical disk or the like, and distributes them. On the other hand, only the terminal holding the decryption key corresponding to the encryption key decrypts the data read from the optical disk or the like using the decryption key to acquire the original digital content, and reproduces the digital content. It can be carried out.
[0004] As a method of encrypting the digital content and recording it on the recording medium, a method of encrypting and recording the digital content itself with an encryption key corresponding to the decryption key held by the terminal, or a method of recording the digital content is performed. There is a method of encrypting and recording with a certain key, and then encrypting and recording the decryption key corresponding to the key with the encryption key corresponding to the decryption key held by the terminal.
[0005] As an example of such a system, for example, "National Technical Report Vol. 43, No. 3, pp. 118-122" (Matsushita Electric Industrial Co., Ltd. Technical General Affairs Center, published on June 18, 1997) is a DVD work. The rights protection system is disclosed. The DVD playback terminal for playing the digital contents recorded on the DVD distributed in this DVD copyright protection system holds in advance the master key determined for each manufacturer of the playback terminal, and the master key. Is used in the decoding process, and finally has a function of decoding and playing back the digital contents recorded on the DVD. The DVD contains a group of keys required for decrypting digital contents, which are encrypted with the master key of each manufacturer.
[0006] [Problem to be Solved by the Invention] By the way, although the decryption key held in the terminal is usually kept secret, an unauthorized person recognizes and exposes the decryption key by analysis of the terminal or other methods. there is a possibility. Once the decryption key held in a certain terminal is exposed, an unauthorized person may create a terminal or software that decrypts digital contents using this decryption key and perform unauthorized copying. As a result, for copyright protection, digital contents cannot be encrypted with an encryption key corresponding to the exposed decryption key, recorded on an optical disk or the like, and distributed.
[0007] For example, considering the DVD playback terminal related to the above-mentioned DVD copyright protection system, if one DVD playback terminal is illegally analyzed and the master key is exposed once, the master key is subsequently exposed. This makes it impossible to distribute encrypted digital content. As a result, after the exposure, the DVD generators, etc. will have to encrypt the digital content using a master key different from the one exposed, record the digital content on the DVD, and distribute it. Since many DVD playback terminals manufactured by the same manufacturer as the DVD playback terminals analyzed in the above hold the same master key, they are recorded on the newly generated and distributed DVD after the exposure. There arises a problem that the digital content cannot be decrypted and played back. That is, if one DVD playback terminal is analyzed by an unauthorized person, many DVD playback terminals will not be able to use the newly generated DVD in the future.
[0008] In order to solve this problem, a separate decryption key is held for each DVD playback terminal, and the digital content or the key required for decrypting the digital content is held by each DVD playback terminal. It is conceivable to record all the encrypted data obtained by encrypting using each encryption key corresponding to the above on a DVD. According to this method, even if some DVD playback terminals are analyzed by an unauthorized person and some decryption keys are exposed, after that, each unexposed decryption held in the DVD playback terminal group is performed. Since all the encrypted data obtained by encrypting digital contents using each encryption key corresponding to the key can be recorded on a DVD and distributed, other than the DVD playback terminal that holds the exposed decryption key. All DVD playback terminals will be able to use newly generated DVDs in the future.
[0009] However, this method also has a drawback that the amount of encrypted data to be recorded on the DVD becomes enormous when the number of DVD playback terminals assumed to be the distribution target of the DVD is enormous. Therefore, the present invention has been made in view of such a problem, and is a data protection system that encrypts data such as digital contents and a key required for decrypting encrypted digital contents and distributes the same data to a large number of terminals. Therefore, after suppressing the increase in the amount of encrypted data to be distributed to some extent, when the decryption key held by the specific terminal is exposed by an unauthorized person by analysis of the specific terminal, the specific one is specified. To provide a data protection system using an encryption technology that enables a terminal to correctly decrypt data and another terminal to correctly decrypt data, and to provide a useful technology for constructing such a data protection system. The purpose.
[Means for Solving the Problems] In order to achieve the above object, the data protection system according to the present invention is provided with three or more terminals, an encryption device, and an encryption key identification device, and is attached to each terminal. It is a data protection system that protects the distribution data by encrypting it with an encryption device, and each terminal stores a decryption key group individually assigned by a predetermined key allocation method, and the encryption device is used to store the decryption key group. The output encrypted distribution data group is acquired, and the encrypted distribution data is decrypted by using the stored decryption key. The predetermined key allocation method is as follows: (a) Each terminal , A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets which is a set including two or more terminals in the element, and the plurality of terminals. Determine two or more terminal sets so that there is a plurality of terminal sets where the relationship that any one terminal set in the set is not a subset of each other terminal set in the plurality of terminal sets is established. Then, (b) determine a separate decryption key for each terminal and each determined terminal set, and (c) This is a method of assigning a decryption key determined corresponding to the terminal and a decryption key defined corresponding to each of all the terminal sets including the terminal to the terminal, and is a method of assigning the encryption key specifying device. Is a device that identifies an encryption key, and is a means for identifying an invalidation terminal that identifies one or more terminals as an invalidation terminal, and among all decryption keys assigned to the terminals by the predetermined key allocation method. When a decryption key other than the decryption key assigned to the invalidation terminal is defined as the valid decryption key, the valid decryption key assigned to the most terminals to which the selected valid decryption key is not assigned is selected. Assuming that the procedure is repeated until there are no terminals to which the selected valid decryption key is assigned, specify the encryption key corresponding to each of the selected valid decryption keys as a result. It is a device having an encryption key identification means, and the encryption device encrypts distribution data by sequentially using all the encryption keys specified by the encryption key identification device, and encrypts the distribution data group. It is characterized by having an encryption means for generating and outputting.
[0011] Here, the distribution data is data that is expected to be recorded and distributed on a recording medium, or distributed through a wired or wireless communication path, and finally reach each terminal. Assuming terminal 1, terminal 2, and terminal 3, the terminal set determined by the above-mentioned predetermined key allocation method includes a set A of terminal 1 and terminal 2, a set B of terminal 1 and terminal 3, and a terminal 2. And there is a set C of the terminal 3, and the decryption key stored and held by the terminal 1 in response to the allocation result by the predetermined key allocation method corresponds to the decryption key unique to the terminal 1, the decryption key A corresponding to the set A, and the set B. The decryption key B stored in the terminal 2 is the decryption key unique to the terminal 2, the decryption key A corresponding to the group A, and the decryption key C corresponding to the group C. The decryption keys to be stored and held are the decryption key unique to the terminal 3, the decryption key B corresponding to the set B, and the decryption key C corresponding to the set C. In this example, if the terminal 2 is illegally analyzed and all the decryption keys stored and held by the terminal 2 are exposed, the terminal 2 is specified as an invalidation terminal, that is, a terminal to be invalidated. When the encryption key is specified by the encryption key specifying means, the encryption key corresponding to the decryption key B is specified.
[0012] Therefore, if the data is encrypted using the encryption key corresponding to the decryption key B and distributed to each terminal, the data cannot be correctly decrypted on the terminal 2 and correctly on the terminals 1 and 3. The data can be decrypted. For the same purpose, data can be encrypted and distributed to each terminal by using an encryption key corresponding to the decryption key unique to terminal 1 and an encryption key corresponding to the decryption key unique to terminal 3. Compared to this method, the method using the encryption key corresponding to the decryption key B described above has the effect that the number of encryption keys used for encryption is small and the amount of encrypted data to be distributed is reduced accordingly. Has.
That is, according to the present invention, in a data protection system that encrypts data such as a key required for decrypting encrypted digital contents and distributes the same data to a plurality of terminals, the encrypted data to be distributed If the decryption key held by a specific terminal is exposed by an unauthorized person after suppressing the increase in the amount, the specific terminal cannot correctly decrypt the data and other terminals. Allows the data to be decrypted correctly.
[0014] Further, the decryption key determination device according to the present invention is for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. A decryption key determination device, (a) so that each of the terminals belongs to at least one of a set of terminals that includes two or more terminals as elements, and further, each of the same one or more terminals. A plurality of terminals included in an element, wherein any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets. Decryption key setting means that determines two or more terminal sets so that a set exists, and (b) associates a separate decryption key for each terminal and each determined terminal set, and for each terminal, the above. Decryption key group allocation that determines the decryption key associated with the terminal by the decryption key setting means and all the decryption keys associated with each of all the terminal sets including the terminal as the decryption key group to be assigned to the terminal. It is characterized by having means.
[0015] Further, the decryption key determination method according to the present invention is for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. A method for determining a decryption key, such that each terminal belongs to at least one of a terminal set which is a set including two or more terminals in an element, and further includes the same one or more terminals in each element. There is a plurality of terminal sets in which the relationship that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets is established. As described above, a terminal set determination step for determining two or more terminal sets, a decryption key associating step for associating different decryption keys for each terminal and for each terminal set determined by the terminal set determination step, and the above. For each terminal, the decryption key associated with the terminal by the decryption key mapping step and all the decryption keys associated with each of all the terminal sets including the terminal are assigned to the terminal. It is characterized by including a decryption key group allocation step determined as a group.
[0016] Further, the decryption terminal system according to the present invention is a decryption terminal system composed of three or more terminals for acquiring and decrypting encrypted data, and each terminal is a predetermined key. Decryption key group storage means that stores decryption key groups individually assigned by the allocation method, encrypted data acquisition means that acquires encrypted data, and data acquired by the encrypted data acquisition means. A decryption means for decrypting using a decryption key stored in the decryption key group storage means is provided, and the predetermined key allocation method is as follows: (a) A set in which each terminal includes two or more terminals as elements. A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets, and any one terminal set in the plurality of terminal sets is the plurality of terminals. Two or more terminal sets are determined so that there is a plurality of terminal sets in which the relationship that the terminal set is not a subset of each other terminal set is established, and (b) each terminal and the determined terminal are determined. A separate decryption key is set for each set, and (c) The method is characterized in that a decryption key determined corresponding to the terminal and a decryption key determined corresponding to each of all the terminal sets including the terminal are assigned to each terminal.
[0017] Further, the decryption terminal according to the present invention is a decryption terminal for acquiring and decrypting encrypted data, and stores decryption key groups individually assigned by a predetermined key allocation method. A decryption key group storage means, an encrypted data acquisition means for acquiring encrypted data, and a decryption key stored in the decryption key group storage means for the data acquired by the encrypted data acquisition means are used. The decoding means and the predetermined key allocation method are as follows: (a) A plurality of terminals in which the terminal is a set including two or more terminals in the case of assuming three or more terminals including the terminal. As if it belongs to a set, it is a plurality of terminal sets each including the terminal as an element, and any one terminal set in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. Determine two or more terminal sets so that there are multiple terminal sets where the relationship that is not established is established, and (b) separate each for the terminal and for each determined terminal set. (C) By assigning the decryption key specified for the terminal and the decryption key specified for each of all terminal sets including the terminal to the terminal. It is characterized by being.
[0018] As a result, for example, when the data of the result encrypted on the recording medium is recorded on each terminal and the recording medium is distributed, the increase in the amount of data recorded on the recording medium is suppressed. So, if the decryption key held by a specific terminal is exposed by an unauthorized person by analysis of a specific terminal, the data cannot be decrypted correctly on that specific terminal and the data can be decrypted correctly on other terminals. It becomes possible to carry out the encryption.
[0019] Further, the encryption key identification device according to the present invention is an encryption key identification device that specifies an encryption key to be used for encrypting distribution data to each of three or more terminals (a). ) A plurality of terminal sets in which each of the terminals belongs to at least one of the terminal sets which is a set including two or more terminals in the element, and further, the same one or more terminals are included in each element. , Two or more such that there is a plurality of terminal sets in which any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets. Determine the terminal set of (b) In addition to the decryption key group associating means for associating different decryption keys for each terminal and each determined terminal set, and the decryption key associated with the terminal by the decryption key setting means for each terminal. Decryption key setting means for associating all decryption keys associated with each of all terminal sets including the terminal with the terminal, invalidation terminal identification means for specifying one or more terminals as invalidation terminals, and the above. When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group mapping means, the selected valid decryption key is used. Assuming that the procedure of selecting the valid decryption key associated with the most unassociated terminals is repeated until there are no terminals that are not associated with the selected valid decryption key. It is characterized by including an encryption key specifying means for specifying an encryption key corresponding to each of all the valid decryption keys selected as a result.
[0020] Further, the encryption device according to the present invention is an encryption device that encrypts data for distribution to three or more terminals, and (a) each terminal has two or more terminals. A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets which are sets included in the element, and any one terminal in the plurality of terminal sets. Two or more terminal sets are determined so that there is a relation that the set is not a subset of each other terminal set in the plurality of terminal sets, and (b) In addition to the decryption key setting means for associating a separate decryption key for each terminal and each determined terminal set, and the decryption key associated with the terminal by the decryption key setting means for each terminal, the terminal. Decryption key group mapping means for associating all the decryption keys associated with each of all the terminal sets including the above with the terminal, invalidation terminal identification means for specifying one or more terminals as invalidation terminals, and the above. When a decryption key other than the decryption key associated with the invalidated terminal among all the decryption keys associated with the terminal by the decryption key group mapping means is defined as the valid decryption key, the selected valid decryption key is used. Assuming that the procedure of selecting the valid decryption key associated with the most unassociated terminals is repeated until there are no terminals that are not associated with the selected valid decryption key. , As a result, the encryption key specifying means for specifying the encryption key corresponding to each of the selected valid decryption keys and all the encryption keys specified by the encryption key specifying means are sequentially used and distributed. It is characterized by including an encryption means for encrypting data for use and generating an encrypted distribution data group, and an output means for outputting the encrypted distribution data group generated by the encryption means to the outside.
[0021] Further, the encryption key identification method according to the present invention is an encryption key identification method for specifying an encryption key to be used for encrypting distribution data to each of three or more terminals. Each terminal is a plurality of terminal sets including the same one or more terminals in each element so that each terminal belongs to at least one of the terminal sets which is a set including two or more terminals in the element. Two or more terminal sets so that there is a relation that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets. A terminal set determination step for determining a terminal set, a decryption key associating step for associating a separate decryption key for each terminal and each terminal set determined by the terminal set determination step, and the decoding for each terminal. In addition to the decryption key associated with the terminal by the key mapping step, the decryption key group mapping step of associating all the decryption keys associated with each of all the terminal sets including the terminal with the terminal. The invalidation terminal identification step that identifies one or more terminals as the invalidation terminal, and the decryption key associated with the invalidation terminal among all the decryption keys associated with the terminal by the decryption key group mapping step. When a decryption key other than the above is defined as a valid decryption key, the procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated is selected and valid. It is characterized by including an encryption key identification step that specifies an encryption key corresponding to each of all the valid decryption keys that have been selected as a result of repeating until there is no terminal to which the decryption key is not associated. To do.
[0022] As a result, for example, when the data of the result of encryption on the recording medium is recorded on each terminal and the recording medium is distributed, the number of encryption keys used for encryption can be suppressed to a relatively small number. Therefore, after suppressing the increase in the amount of data recorded on the recording medium, when the decryption key held by the specific terminal is exposed by an unauthorized person by analysis of the specific terminal or the like, the specific terminal is exposed. Then, the data cannot be decrypted correctly, and the encryption can be performed so that the data can be decrypted correctly on other terminals.
[Embodiment of the Invention] <Embodiment 1> Hereinafter, the data protection system according to the first embodiment of the present invention will be described with reference to the drawings. <Overall Configuration> FIG. 1 is a schematic configuration diagram of a data protection system 100 according to a first embodiment of the present invention.
As shown in the figure, the data protection system 100 includes an encryption device 101, a plurality of decryption devices (terminals) 103a to 103n, and a key setting system 104, and is a content composed of digital data indicating video, audio, and the like. This is a system for encrypting data, recording it on an optical disk 102 such as a DVD-ROM, and distributing it to a plurality of terminals.
[0025] Here, the key setting system 104 is a system for determining an encryption key to be set in the encryption device 101 and a decryption key to be individually set in the decryption devices 103a to 103n. The encryption device 101 is a device that holds an encryption key specified by the key setting system 104, encrypts the contents, and records the contents on the optical disk 102. As for the optical disc 102, it is assumed that a large number of optical discs 102 having completely the same recorded contents are duplicated.
[0026] The decryption devices 103a to 103n are a large number of terminals, for example, 1 billion units, and each decryption device holds a decryption key individually determined by the key setting system 104, and is transmitted from the optical disk 102. It is a device that reads and decrypts encrypted content (hereinafter referred to as "encrypted content") and reproduces the content obtained by decryption.
[0027] When the data protection system 100 is used to protect the copyright of the content, the key setting system 104 and the encryption device 101 are operated by an organization that manages the copyright protection, and the decryption device. Is expected to be used by general users. In addition, the key setting system 104 is basically used once to determine the decryption key for each decryption device, once to identify the encryption key to be used first, and further to be specific. Every time it is found that the decryption key held in the decryption device is exposed due to unauthorized analysis of the decryption device, the specific decryption device cannot decrypt the encrypted content recorded on the optical disk. It is used to identify a new encryption key to be used when newly recording the content on the optical disk in the encryption device 101.
[0028] Hereinafter, the encryption device 101, the decryption devices 103a to 103n, and the key setting system 104 will be described in more detail. <Configuration of Encryption Device> FIG. 2 is a functional configuration diagram of the encryption device 101 and the decryption device 103a. As shown in the figure, the encryption device 101 includes a content storage unit 201, a random number generation unit 202, an encryption key group storage unit 203, a key encryption unit 204, a content encryption unit 205, and an output unit 206.
[0029] Here, the content storage unit 201 is a storage device such as a hard disk that stores content composed of digital data indicating video, audio, and the like. The random number generator 202 has a function of generating a random number that serves as a key used for encrypting the content (hereinafter, referred to as a content key). The content key is, for example, 64-bit data composed of random numbers.
[0030] The encryption key group storage unit 203 stores one or a plurality of encryption keys specified by the key setting system 104, and the decryption device side specifies a decryption key corresponding to the stored encryption key. It is a storage device such as a memory for storing key specific information used for performing the key. When a new encryption key is specified by the operation of the key setting system 104, the encryption key held in the encryption key group storage unit 203 before the identification is deleted and newly specified. Only the encrypted key is stored in the encryption key group storage unit 203. The new encryption key and the key identification information corresponding to the encryption key may be stored, for example, by being input by an operator or by receiving from the key setting system 104. Good.
The key encryption unit 204 encrypts the content key acquired from the random number generation unit 202 using each encryption key stored in the encryption key group storage unit 203, and the result is encrypted. It has a function of transmitting each content key (hereinafter referred to as "encrypted content key") to the output unit 206. The content encryption unit 205 has a function of encrypting the content stored in the content storage unit 201 using the content key acquired from the random number generation unit 202 and transmitting the resulting encrypted content to the output unit 206. ..
[0032] Further, the output unit 206 includes hardware capable of recording data on the optical disk, acquires key identification information from the encryption key group storage unit 203, and transmits the key identification information and the content encryption unit 205. It has a function of recording the encrypted content and the encrypted content key transmitted from the key encryption unit 204 on the optical disk 102.
[0033] By recording the encryption device 101, the encrypted content, one or more encrypted content keys, and the key identification information are recorded on the optical disk 102. The number of encrypted content keys recorded on the optical disk 102 matches the number of encryption keys specified by the key setting system 104 and stored in the encryption key group storage unit 203.
[0034] Such an encryption device 101 includes a CPU, a memory, and the like as hardware, and has the functions of the above-mentioned random number generation unit 202, key encryption unit 204, content encryption unit 205, and output unit 206. All or part of it is realized by executing the control program stored in the memory by the CPU. <Structure of Decoding Device> Decrypting device 103a is a terminal for playing an optical disc, and as shown in FIG. 2, acquisition unit 211, decoding key group storage unit 212, decoding key selection unit 213, key decoding unit 214, and content decoding unit. It has 215 and a reproduction unit 216.
[0035] Here, the acquisition unit 211 includes hardware capable of reading data from the optical disk, reads the encrypted content from the optical disk 102 and transmits the encrypted content to the content decoding unit 215, and reads the encrypted content key from the optical disk 102 to obtain the key. It has a function of transmitting to the decoding unit 214, reading key identification information from the optical disk 102, and transmitting the key identification information to the decryption key selection unit 213.
[0036] The decryption key group storage unit 212 is a storage device such as a non-volatile memory that stores a plurality of decryption keys and the like determined for the decryption device 103a by the key setting system 104. The decryption key is stored, for example, in the manufacturing process of the decryption device. The decryption key selection unit 213 determines and uses which of the decryption key groups stored in the decryption key group storage unit 212 can be used based on the key identification information transmitted from the acquisition unit 211. It has a function to select one decryption key that can be used.
[0037] The key decryption unit 214 acquires an encrypted content key that can be decrypted by using the decryption key selected by the decryption key selection unit 213 through the acquisition unit 211, and obtains the acquired encrypted content key as the decryption key. The content key is generated by decrypting using. The content decryption unit 215 has a function of generating content by decrypting the encrypted content transmitted from the acquisition unit 211 using the content key generated by the key decryption unit 214 and transmitting the content to the playback unit 216.
[0038] Further, the reproduction unit 216 has a function of reproducing the content transmitted from the content decoding unit 215. If the content handled by the data protection system 100 is moving image data according to a compression method defined by, for example, MPEG (Moving Picture Expert Group), the playback unit 216 may be, for example, a so-called MPEG decoder or the like. Therefore, it is necessary to include a function of extending the content and outputting a video signal.
[0039] Such a decoding device 103a includes a CPU, a memory, and the like as hardware, and includes the acquisition unit 211, the decryption key selection unit 213, the key decoding unit 214, the content decoding unit 215, and the playback unit 216 described above. All or part of the functions are realized by executing the control program stored in the memory by the CPU.
[0040] The plurality of decoding devices 103b to 103n other than the decoding device 103a also have the same configuration as the decoding device 103a. However, all or part of the contents stored in the decryption key group storage unit 212 differs for each decryption device. <Configuration of key setting system> FIG. 3 is a functional configuration diagram of the key setting system 104.
As shown in the figure, the key setting system 104 includes a key information storage unit 301, a key information generation unit 302, an invalidation terminal identification unit 303, a key information update unit 304, a decryption key determination unit 305, and an encryption key identification unit. It has a part 306. Here, the key information storage unit 301 is a storage device such as a hard disk for storing key information described later.
[0042] The key information generation unit 302 determines the tree structure so that each of the decoding devices constituting the data protection system 100 corresponds to the node of the lowest layer of the hierarchical quadtree tree structure, and in the tree structure. One or more keys are assigned to each node, and key information indicating the assigned key etc. for each node is generated. The key information is information used to identify the encryption key and the decryption key, and serves as a criterion for determining whether or not each key assigned to each node can be used as the encryption key. Contains invalidation information. This key information and the tree structure of the quadtree will be described in detail later.
[0043] The invalidation terminal identification unit 303 receives the designation of the decoding device to which the decryption key held is exposed from the operator via the input device such as the keyboard and the pointing device, and invalidates the designated decoding device. It has a function to specify as a terminal to be converted (hereinafter referred to as "disabled terminal"). The invalidation terminal indicates a decryption device that needs to perform encryption so that the terminal cannot correctly decrypt the encrypted content in the encryption of the content.
[0044] The key information update unit 304 has a function of updating the invalidation information in the key information stored in the key information storage unit 301 based on the invalidation terminal specified by the invalidation terminal identification unit 303. .. The decryption key determination unit 305 has a function of determining a plurality of decryption keys to be set for each decryption device based on the key information stored in the key information storage unit 301. The decryption key determined for each decryption device is stored in the decryption key group storage unit of the decryption device together with the information indicating the node associated with the decryption key by the key information, for example, in the manufacturing process of the decryption device. Stored. Therefore, the key setting system 104 transmits, for example, the determined decryption key and the information indicating the correspondence between the decryption key and the node to, for example, the manufacturing system for manufacturing the decryption device.
[0045] Further, the encryption key identification unit 306 has a function of specifying one or a plurality of encryption keys to be set in the encryption device based on the key information stored in the key information storage unit 301. By showing the correspondence between the specified encryption key and the node, the key identification information that serves as a criterion for determining which decryption key should be used at the time of decryption is output together with the specified encryption key.
[0046] This output is, for example, transmission to the encryption device 101 or recording on a portable recording medium. When the encryption key identification unit 306 records the encryption key on a portable recording medium, the operator in operation causes the contents of the recording medium to be stored in the encryption key group storage unit 203 of the encryption device 101. Must be copied. <Key information> Hereinafter, the key information generated by the key information generation unit 302 and stored in the key information storage unit 301 will be described.
First, the tree structure of a quadtree will be described. FIG. 4 is a diagram showing the tree structure of a quadtree. This tree structure is constructed so that each node (hereinafter, also referred to as "leaf") constituting the lowest layer node group 406 and a decoding device (terminal) have a one-to-one correspondence, and from one node. Is a tree structure with branches to four nodes. Here, a structure having branches from one node to n nodes is called an n-segment tree, and a structure having branches to four nodes is called a quadtree. Also, one node that has a branch to the four nodes is called the parent node for the four nodes, the four nodes are called the child nodes for the parent node, and the top-level node 405 is rooted. It will be referred to as.
[0048] When the number of decoding devices in the data protection system 100 is not a factorial prime of 4, the number of nodes in the lowest layer is the smallest number among the factorial primes of 4 that is larger than the number of decoding devices. Here, for the sake of simplicity, it is assumed that the number of decoding devices matches the number of nodes in the lowest layer. The key information generation unit 302 increases the uppermost layer 401 of the tree structure shown in FIG. 4 to level 0, the next lower layer 402 to level 1, and the next lower layer by one level to the lowest level. The layer 403 one layer above is defined as level D-1, the lowest layer 404 is defined as level D, and each node at each level determines the relative number at each level in order from 1. Therefore, the node with relative number 1 at level D corresponds to the decoding device 103a, the node with relative number 2 at level D corresponds to decoding device 103b, and the node with relative number 4 to the D power at level D is the last decoding device. Corresponds to 103n.
FIG. 5 is a diagram showing an example of a quadtree tree structure when the number of decoding devices is 64. In the example shown in the figure, the tree structure of the quadtree is constructed so that there are 64 leaves, so the lowest layer is level 3. Next, the invalidation information defined corresponding to each node will be described.
[0050] The invalidation information for a certain node is a flag indicating whether or not the node is an invalid node for four child nodes when the node is a parent node, and a flag for a node having a small relative number. It is the information combined in order from. The flag takes a value of 1 if it is an invalid node and 0 if it is not an invalid node. Therefore, for example, if the four child nodes are not invalid nodes, the invalidation information of the parent node is "0000", and if the four child nodes are invalid nodes, the invalidation information of the parent node is "1111".
However, for the leaf, the invalidation information is "1111" if the decoding device corresponding to the leaf is an invalidation terminal, and "0000" if it is not an invalidation terminal. The invalid node is a leaf corresponding to the invalidation terminal, or a node arriving from the leaf corresponding to the invalidation terminal toward the upper layer. Therefore, it can be said that the invalid node is a node whose corresponding invalidation information has a value other than "0000".
[0052] Here, the node "reaching" from a specific node is assumed to be a chain between each node having a relationship between the parent node and the child node, and the node is from the specific node. A node connected by one or more chains in either the upper layer direction or the lower layer direction. Therefore, in the tree structure, the lower node that is reached by passing over one or more chains from the upper node toward the lower layer is the node that arrives from the upper node, and conversely, the upper node. Is a node that can be reached from the node below it. For example, you can reach the route from any leaf, you can reach any leaf from the route, but you cannot reach another leaf from one leaf.
[0053] Before the decryption key held by the decryption device is exposed, the invalidation terminal does not exist, so the invalidation information for all the nodes takes a value of "0000". 6 and 7 are diagrams showing an example of route invalidation information. The example of FIG. 6 shows that the invalidation information of the route is "0000" when all the child nodes of the route are not invalid nodes.
In the example of FIG. 7, the invalid node is indicated by a cross, and the invalidation information of the route is "1000" when only the child node of the root whose relative number is 1 is the invalid node. It shows that it becomes. Next, the key assigned to each node will be described. The key information generation unit 302 separately assigns an encryption key and a pair of decryption keys corresponding to the encryption key to each node. A unique set of keys is assigned to each decryption device for the leaf, and a plurality of sets of keys are assigned to the nodes other than the leaf as shown below.
FIG. 8 is a diagram showing keys assigned to nodes in the level 0 and level 1 hierarchies of a quadtree tree structure. In the figure, 0-1K0000, 0-1K0001, etc. represent the encryption key and the corresponding decryption key collectively for convenience. In addition, it is possible to determine in advance whether the data protection system 100 adopts a method in which the encryption key and the decryption key have different values or a method in which the encryption key and the decryption key have the same value. When adopting a method that takes different values, for example, the decryption key represented by 0-1K0000 and the encryption key represented by 0-1K0000 have different values and are encrypted in the data protection system 100. When a method in which the key and the decryption key take the same value is adopted, for example, the encryption key and the decryption key represented by 0-1K0000 have the same value.
[0056] Hereinafter, the expression that the decryption key is assigned to each node or the expression that the encryption key is assigned to each node is used, but in reality, the decryption key and the encryption key are separate. When the method of taking a value is adopted, the decryption key and the encryption key corresponding to the decryption key are assigned to each node, and when the method of adopting the method in which the decryption key and the encryption key take the same value, the decryption key is decrypted. A key that is both a key and an encryption key is assigned to each node. As a result, the decryption key or the like assigned in the key information is set. The encryption key and the decryption key are, for example, 64-bit data.
As shown in FIG. 8, 11 decryption keys are assigned to the nodes other than the leaf. Here, among the possible values of "0000", "1000", etc. of the invalidation information for a certain node, the number of "1" is less than (n-1) when the tree structure of the n-branch tree is used. The value that becomes is called an invalidation pattern. Therefore, the invalidation pattern in the quadtree is "0000", "0001", "0010", "0011", "0100", "0101", "0110" where the number of "1" is less than 3. , "1000", "1001", "1010" and "1100" exist, and each node other than the leaf is assigned 11 decryption keys for all invalidation patterns.
[0058] Here, a key for a node having a relative number B of level A and having an invalidation pattern of X is expressed as "A-BKX". Therefore, "0-1K0000" indicates that the invalidation pattern for the node with the relative number 1 of level 0 is the decryption key or the like corresponding to "0000". FIG. 9 is a diagram showing a configuration of key information stored in the key information storage unit 301.
As shown in the figure, the key information 500 is information in which the node ID 501 of the node, the invalidation pattern 502, the key 503, and the invalidation information 504 are associated with each node. The node ID 501 is an ID indicating a level indicating the location of the node in the tree structure and a relative number. For example, the node ID of the node having the relative number B of the level A is expressed as "AB".
[0060] The invalidation pattern 502 is a value in which the number of "1" is less than 3 among the possible values of the invalidation information as described above. The key 503 is a decryption key and an encryption key assigned to the node indicated by the corresponding node ID. The invalidation information 504 is invalidation information about the node indicated by the corresponding node ID, and the initial value is "0000".
[0061] In the key information, there is no invalidation pattern corresponding to the leaf, and the key 503 for the leaf is a set of decryption key and encryption key. <Key allocation process> Hereinafter, after the key information is stored in the key information storage unit 301 by the key information generation unit 302 in the key setting system 104, the decryption key determination unit 305 sets each of the decryption devices 103a to 103n. The key allocation process performed to determine the decryption key to be output, that is, to assign a plurality of decryption keys to each decryption device will be described.
FIG. 10 is a flowchart showing a key allocation process executed by the decryption key determination unit 305. First, the decryption key determination unit 305 sets the decryption device (terminal) to which the relative number 1 of the leaf in the tree structure of the quadtree is associated as the allocation target terminal (step S11), and corresponds to the allocation target terminal. Focusing on the leaf, that is, the node of the lowest layer, one identification key assigned to that node (node of interest) is specified (step S12). Note that the focus on a node specifically means, for example, storing the address in the storage area of the information about the node in the key information in a variable or the like for internal processing.
[0063] Subsequently, the decryption key determination unit 305 stores the node (parent node) above the node of interest, which indicates that the node of interest is valid, that is, not an invalid node, in the key information storage unit 301. All the decryption keys corresponding to the invalidation pattern defined in the key information are specified, and the parent node is newly defined as the node of interest (step S13).
[0064] Following step S13, the decryption key determination unit 305 determines whether the current node of interest is the root (step S14), and if it is not the root, the process of step S13 until the current node of interest becomes the root. Is repeated. If the current node of interest is the root in step S14, the decryption key determination unit 305 determines as the decryption key to set all the keys specified in steps S12 and S13 for the allocation target terminal (step S15). , It is determined whether or not the allocation target terminal is the last terminal, that is, whether or not it is the decoding device associated with the leaf having the largest relative number (step S16), and if it is the last terminal, the key. Finish the allocation process.
[0065] Further, when it is determined in step S16 that the allocation target terminal is not the last terminal, the decryption key determination unit 305 is the leaf corresponding to the terminal next to the current allocation target terminal, that is, the current allocation target terminal. The decoding device associated with the leaf whose relative number is one higher than that of the leaf is newly defined as the allocation target terminal (step S17), and the process of step S12 is performed.
By such a key allocation process, a decryption key group to be set for each decryption device is determined, and in response to this, each decryption device is configured to hold the determined decryption key group. Will be done. FIG. 11 shows the decryption key group 905 assigned to the decryption device (terminal 1) corresponding to the leaf of the relative number 1 of level 3 and the decryption key group 905 determined by the key allocation process when it is assumed that there are only 64 decryption devices. It is a figure which shows.
[0067] Note that 3-1K in the figure represents the only decryption key assigned to the leaf 904 of the relative number 1 of level 3. Assuming that there are only 64 decryption devices, as shown in FIG. 11, the terminal 1 has the decryption key 3-1K assigned to the leaf 904 of the relative number 1 of level 3 and the decryption key 3-1K of the leaf. Of the decryption keys assigned to the level 2 relative number 1 node 903, which is the parent node one layer above, the decryption key corresponding to the invalidation pattern indicating that the first child node is not an invalid node, that is, " 7 decryption keys 2-1K0000, 2-1K0001, 2-1K0010 corresponding to 7 invalidation patterns "0000", "0001", "0010", "0011", "0100", "0101" and "0110" , 2-1K0011, 2-1K0100, 2-1K0101 and 2-1K0110, and the first decryption key assigned to node 902 with level 1 relative number 1 which is the parent node one layer above it. Seven decryption keys 1-1K0000, 1-1K0001, 1-1K0010, 1-1K0011, 1-1K0100, 1-1K0101 and 1-1K0110, and more, corresponding to the invalidation pattern indicating that the child node is not an invalid node. Seven decryptions corresponding to the invalidation pattern indicating that the first child node is not an invalid node among the decryption keys assigned for the level 0 relative number 1 node that is the parent node one layer above, that is, root 901. A total of 22 decryption keys are assigned, including keys 0-1K0000, 0-1K0001, 0-1K0010, 0-1K0011, 0-1K0100, 0-1K0101 and 0-1K0110.
Therefore, in this case, the 22 decryption keys assigned to the decryption key group storage unit 212 of the terminal 1 are stored in the decryption key group storage unit 212 of the terminal 1, for example, in the manufacturing process of the terminal 1. The invalidation pattern corresponding to each node other than the leaf is "1" if the child node of that node is an invalid node, "0" if it is a valid node that is not an invalid node, and the relative number within the level of the child node. The information is concatenated in ascending order of, and assigning the decryption key to the invalidation pattern is based on all terminals corresponding to all the leaves that can be reached from all the child nodes indicated as valid nodes in the invalidation pattern. Corresponds to assigning a decryption key to a set of terminals to be used. Therefore, each terminal is assigned a decryption key unique to that terminal and a decryption key assigned to all terminal sets including that terminal.
<Identification of encryption key> The encryption key identification unit 306 of the key setting system 104 has the encryption assigned to the root in the state where there is no invalidation terminal, that is, in the state where no decryption key is exposed. The encryption key 0-1K0000, that is, the encryption key corresponding to the decryption key 0-1K0000 is specified as the encryption key to be set in the encryption key group storage unit 203 of the encryption device 101.
[0070] On the other hand, the encryption device 101 receives the specified encryption key and the key identification information for identifying the decryption key 0-1K0000 assigned to the root in the tree structure from the key setting system 104. It is stored in the encryption key group storage unit 203 by such means. When recording the content on the optical disk 102, the encryption device 101 key-encrypts the content key generated from the random number generation unit 202 by using the encryption key stored in the encryption key group storage unit 203. It is encrypted in unit 204, the encrypted content key obtained by the encryption is associated with the key identification information, recorded on the optical disk 102 by the output unit 102, and stored in the content storage unit 201 using the content key. The content is encrypted by the content encryption unit 205, and the encrypted content obtained by the encryption is recorded on the optical disk 102 by the output unit 102.
Hereinafter, the invalidation information update process executed by the key information update unit 304 in the key setting system 104 will be described. When the invalidation terminal is specified by the invalidation terminal identification unit 303, the key information update unit 304 has a quadrant tree structure corresponding to the invalidation terminal among the key information stored in the key information storage unit 301. After setting the invalidation information about the leaf in "1111" to indicate that the leaf is an invalid node, the invalidation information update process for updating the invalidation information corresponding to each node in the key information is performed. Do.
FIG. 12 is a flowchart showing an invalidation information update process executed by the key information update unit 304. First, the key information update unit 304 pays attention to the layer one layer above the lowest layer in the tree structure of the quadtree (step S21). In other words, if the lowest layer is level D, focus on the level (D-1) layer.
Subsequently, the key information update unit 304 pays attention to each node of the layer of interest (layer of interest) in ascending order of relative number, and about four child nodes of the node of interest (node of interest). Update the invalidation information for the node of interest so that it matches the combination pattern of invalid nodes in (step S22). For example, if the four child nodes of the node of interest are "invalid node", "not invalid node", "not invalid node", and "not invalid node" in ascending order of relative number, the focus node The invalidation information is "1000".
After step S22, the key information update unit 304 determines whether the current layer of interest is the highest layer, that is, the level 0 layer (step S23), and if it is not the highest layer, 1 of the layer of interest. Focusing on the next higher layer (step S24), the process of step S22 is performed. In the determination of step S23, the key information update unit 304 repeats steps S22 to S24 until the current layer of interest becomes the highest layer, and if the current layer of interest becomes the highest layer in the determination of step S23, it is invalid. The conversion information update process is completed.
[0075] As a result, in the tree structure of the quadtree, the invalidation information for all the nodes that can be reached by tracing from the leaf corresponding to the invalidation terminal toward the upper layer takes a value other than "0000". .. Next, the invalidation terminal is identified by the invalidation terminal identification unit 303 of the key setting system 104, and after the invalidation information in the key information is updated by the key information update unit 304, the encryption key identification unit 306 encrypts. The key identification process performed to specify the encryption key group to be set in the encryption key group storage unit 203 of the device 101 will be described.
[0076] FIG. 13 is a flowchart showing a key identification process executed by the encryption key identification unit 306. First, the encryption key identification unit 306 pays attention to the node of the highest layer in the tree structure of the quadtree, that is, the root (step S31). Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node of interest (node of interest), and invalidates the node of interest that matches the invalidation information of the node of interest. It is determined whether the pattern exists (step S32), and if the invalidation pattern exists, the encryption key corresponding to the invalidation pattern for the node of interest should be set in the encryption device 101. Only when it is specified as a key (step S33) and it is determined that the layer one layer below the focus node is not the lowest layer in the tree structure (step S34), if there is an invalid node among the child nodes of the focus node. All of the invalid nodes are defined as the nodes to be focused on (step S35).
[0077] In step S32, when it is determined that there is no invalidation pattern matching the invalidation information, the encryption key identification unit 306 determines whether the layer to which the child node of the node of interest belongs is the lowest layer in the tree structure. It is determined whether or not (step S36), and if the layer to which the child node of the focus node belongs is the lowest layer, the encryption key assigned to the child nodes of the focus node other than the leaf corresponding to the invalidated terminal. Is specified as the encryption key to be set in the encryption device 101 (step S37).
[0078] In step S36, when it is determined that the layer to which the child node of the node of interest belongs is not the lowest layer, the encryption key identification unit 306 determines all the child nodes of the node of interest as the nodes to be focused (step). S38). After step S35, S37, S38, or after determining in step S34 that the layer one layer below the node of interest is the lowest layer, the encryption key identification unit 306 has a node of interest that has not yet been focused. It is determined whether or not to do so (step S39), and if there is a node of interest that has not been focused yet, one of the nodes of interest that has not been focused is newly focused (step S40), and step S32. Return to the judgment process of.
[0079] In step S39, if it is determined that there is no node to be focused on that has not yet been focused, the encryption key identification unit 306 ends the key identification process. As a result, all the encryption keys specified in steps S33 or S37 are output from the encryption key identification unit 306 together with the key identification information and stored in the encryption key group storage unit 203 of the encryption device 101. Become.
[0080] FIG. 14 is a diagram showing an encryption key or the like in a state where there is no invalidation terminal when it is assumed that there are only 64 decryption devices. In this case, the encryption key stored in the encryption key group storage unit 203 of the encryption device 101 and used for encrypting the content key when recording the content on the optical disk 102 is , Encryption key 0-1K0000, that is, one encryption key corresponding to the decryption key represented by 0-1K0000.
[0081] Fig. 15 is a diagram showing an encryption key and the like in a state where the terminal 1 is an invalidated terminal when it is assumed that there are only 64 decryption devices. If only terminal 1 is an invalidation terminal, as a result of the invalidation information update processing described above, the key information stored in the key information storage unit 301 will be obtained from node 1103, which is the relative number 1 of the level 2 layer. The invalidation information becomes "1000", the invalidation information of the node 1102 having the relative number 1 of the level 1 layer becomes "1000", and the invalidation information of the root 1101 of the level 0 layer becomes "1000".
On the premise of this, the specific processing contents of the above-mentioned key identification processing (see FIG. 13) will be described below based on the example of FIG. First, the encryption key identification unit 306 pays attention to the uppermost node, that is, the route 1101 (step S31). Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node of interest (the node of interest), and is "1000" which is invalidation information of the node 1101. Matches one of the 11 types of invalidation patterns described above (step S32), so the encryption key 0-1K1000 corresponding to the invalidation pattern is specified as the encryption key to be set in the encryption device 101. (Step S33) Since the layer one layer below the node of interest is the level 1 layer and not the lowest layer (step S34), we plan to focus on node 1102, which is an invalid node that exists among the child nodes of the node of interest. Defined as a node (step S35).
[0083] After step S35, the encryption key identification unit 306 has node 1102 as a node of interest that has not yet been focused on (step S39), so that node 1102 is newly set as the node of interest (step S40), and the step is taken. Return to the judgment process of S32. Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node of interest, and the invalidation information "1000" of the node 1102 is the above-mentioned 11 types. Since it matches one of the invalidation patterns (step S32), the encryption key 1-1K1000 corresponding to the invalidation pattern is specified as the encryption key to be set in the encryption device 101 (step S33), and the node of interest Since the layer one layer below is the level 2 layer and not the lowest layer (step S34), node 1103, which is an invalid node existing among the child nodes of the node of interest, is defined as the node of interest (step S35). ..
[0084] After step S35, the encryption key identification unit 306 has node 1103 as a node of interest that has not yet been focused (step S39), so that node 1103 is newly set as the node of interest (step S40). Return to the judgment process of S32. Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node of interest, and the invalidation information "1000" of the node 1103 is the above-mentioned 11 types. Since it matches one of the invalidation patterns (step S32), the encryption key 2-1K1000 corresponding to the invalidation pattern is specified as the encryption key to be set in the encryption device 101 (step S33), and the node of interest Since the layer one layer below is the level 3 layer and the lowest layer (step S34), step S35 is skipped and there is no target node that has not been focused yet (step S39), so the key is specified. Finish the process.
[0085] As a result of this key identification process, an encryption key group stored in the encryption key group storage unit 203 of the encryption device 101, which is used for encrypting the content key when recording the content on the optical disk 102. The encryption key groups to be used are the encryption keys 0-1K1000, 1-1K1000, and 2-1K1000, respectively. The encryption key identification unit 306 creates key identification information from the node ID, invalidation pattern, etc. in the key information 500 (see FIG. 9) corresponding to each encryption key specified by the above-mentioned key identification process. This key identification information is stored in the encryption key group storage unit 203 of the encryption device 101, and is recorded on the optical disk 102 together with the contents and the like by the encryption device 101.
[0086] FIG. 16 is a diagram showing an example of key identification information corresponding to the encryption key shown in FIG. The example in the figure is an example in which the key identification information is configured by combining the character string which is the node ID in the key information 500, the character "K", and the character string of the invalidation pattern. When the output unit 206 of the encryption device 101 records the key identification information shown in FIG. 16 on the optical disk, the encrypted content generated by encryption using the encryption key 0-1K1000 on the optical disk. This order can identify the key, the encrypted content key generated by encryption using the encryption key 1-1K1000, and the encrypted content key generated by encryption using the encryption key 2-1K1000. Record in a way like this.
<Decryption of Encrypted Content> Hereinafter, each encrypted content key generated by encryption using each encryption key shown in FIG. 15, the encrypted content, and the key identification information shown in FIG. 16 are recorded. A specific procedure for decoding and reproducing the content by one decoding device 103n from the optical disk 102 will be described. Since the decoding device 103n has the same configuration as the decoding device 103a and differs only in the contents of the decoding key group storage unit 212, each part of the decoding device 103n will be described here using the reference numerals in FIG.
The decryption key selection unit 213 of the decryption device 103n reads the key identification information from the optical disk 102 via the acquisition unit 211, and associates each decryption key held in the decryption key group storage unit 212 with the node. By collating the indicated information, for example, the node ID and invalidation pattern information corresponding to each decryption key in the key information 500 with the key identification information, the encryption key specified by the key identification information is the same. A decryption key corresponding to the same invalidation pattern for the node, that is, a decryption key corresponding to the encryption key is selected, and the decryption key is taken out from the decryption key group storage unit 212 and given to the key decryption unit 214. In response to this, the key decryption unit 214 decrypts the encrypted content key encrypted with the encryption key acquired through the acquisition unit 211 using the decryption key. By such a procedure, for example, if the decryption key 0-1K1000 is included in the decryption key group storage unit 212 of the decryption device 103n, the decryption device 103n records the key identification information shown in FIG. The content key encrypted using the encryption key 0-1K1000 is decrypted using the decryption key 0-1K1000 to obtain the content key.
After obtaining the content key, the decryption device 103n decrypts the encrypted content acquired through the acquisition unit 211 using the content key in the content decryption unit 215 to obtain the content. The content is reproduced in the reproduction unit 216. Assuming that the terminal 1 in FIG. 15 is the decoding device 103a, the decoding device 103a holds only the 22 decryption keys shown in FIG. 11, and is 0-1K1000, 1-1K1000, and 2-. Since none of the decryption keys of 1K1000 is held, each encrypted content key generated by encryption using each encryption key shown in FIG. 15 and recorded on the optical disk 102 cannot be correctly decrypted. Therefore, the encrypted content recorded on the optical disk 102 cannot be correctly decrypted, and the content cannot be played back.
<Discussion> In the data protection system 100, the number of decryption devices is about 1 billion (4).<sup>15</sup>In the case of a stand), it is necessary to construct a quadtree tree structure consisting of layers from level 0 to level 15. In this case, if one decryption device is used as an invalidation terminal, it exists on the route from the leaf to the root corresponding to the one invalidation terminal in the key identification process by the encryption key identification unit 306. The encryption key corresponding to one invalidation pattern for each of the 15 nodes except the leaf will be identified, and as a result, the encryption device 101 will use 15 to encrypt the content key. Individual encryption keys will be used. At this time, the encrypted content, the 15 encrypted content keys, and the key identification information are recorded on the optical disk 102.
[0091] Further, for example, about 16,000 units (4) in the approximately 1 billion decoding devices.<sup>7</sup>Assuming that the decryption device of (unit) is an invalid terminal, about 131,072 (4) are used to encrypt the content key in the encryption device 101.<sup>7</sup>× (15-7) encryption keys) will be used. At this time, the encrypted content, about 131,072 encrypted content keys, and key identification information are recorded on the optical disk 102.
[0092] If one encrypted content key is 64 bits, that is, 8 bytes (Byte), about 131,072 encrypted content keys are about 1 megabyte (MB) in total. Therefore, it can be said that the total amount of data of the encrypted content key is sufficiently small with respect to the capacity of a general optical disc. Hereinafter, the total amount of data of the encrypted content key when encryption is performed by a method other than the present embodiment will be examined. (1) Under the assumption that the encrypted content key is 8 bytes, the number of decryption devices is about 1 billion, and about 16,000 decryption devices are invalidated terminals, all decryption devices are different. One decryption key is held, and the content key is encrypted using each encryption key corresponding to the decryption key held by all decryption devices other than the invalidation terminal, recorded on the optical disk, and distributed. If the method is adopted, the total number of encrypted content keys to be recorded on the optical disk will be about 999,984,000, and the total amount of data of the encrypted content will be as large as about 7600 megabytes, which is practical. Not the target. (2) Under the same assumption, tentatively, only one decryption key is assigned to each node in the tree structure of the quadrant in which the leaf corresponds to each decryption device, and each decryption device is assigned to the decryption device. Keep the decryption key assigned to each of the corresponding leaf and all the nodes that can be reached by tracing from that leaf to the upper layer, and trace from one leaf corresponding to the invalidated terminal to the upper layer. A method of encrypting the content key using the encryption key assigned to each node that is not an invalid node among all the child nodes of all the nodes that can be reached (that is, the invalid node), recording it on the optical disk, and distributing it. If adopted, the lowest level of the tree structure would be 15, and the total number of encrypted content keys to be recorded on the optical disk would be approximately 393,216 (4).<sup>7</sup>× (15-7) × 3), and the total amount of data of the encrypted content is about 3 megabytes, which is considerably larger than that of the data protection system 100 according to the present embodiment. (3) Under the same assumption, tentatively, only one decryption key is assigned to each node in the tree structure of the bisector in which the leaf corresponds to each decryption device, and each decryption device is assigned to the decryption device. Keep the decryption key assigned to each of the corresponding leaf and all the nodes that can be reached by tracing from that leaf to the upper layer, and trace from one leaf corresponding to the invalidated terminal to the upper layer. A method of encrypting the content key using the encryption key assigned to each node that is not an invalid node among all the child nodes of all the nodes that can be reached (that is, the invalid node), recording it on the optical disk, and distributing it. If adopted, the level of the lowest layer of the tree structure will be 30, and the total number of encrypted content keys to be recorded on the optical disk will be about 262,144 (2).<sup>14</sup>× (30-14)), and the total amount of data of the encrypted content is about 2 megabytes, which is considerably larger than that of the data protection system 100 according to the present embodiment. <Embodiment 2> Hereinafter, the data protection system (hereinafter, referred to as second data protection system) according to the second embodiment of the present invention will be described with reference to the drawings.
[0093] The second data protection system is different from the data protection system 100 in that a plurality of tree structures used for determining the decryption key and the encryption key are used. The second data protection system includes basically the same components (see FIGS. 1 to 3) as the data protection system 100 shown in the first embodiment. Therefore, here, the components of the second data protection system will also be described using the reference numerals shown in FIGS. 1 to 3. Here, the second data protection system will be mainly described in terms of differences from the data protection system 100, and the description of the same points will be omitted.
[0094] The specific operation contents of the key information generation unit 302, the key information update unit 304, the decryption key determination unit 305, and the encryption key identification unit 306 in the second data protection system are different from the corresponding parts in the data protection system 100. However, the basic processing contents (procedures shown in FIGS. 10, 12, and 13) performed by each part are almost the same, and the key information storage unit 301 in the second data protection system has a layer other than the lowest layer. Each node is associated with 11 sets of decryption keys and encryption keys along with the 11 types of invalidation patterns shown in FIG. 9 in the first embodiment, and each node in the lowest layer has one set of decryption keys and encryption keys. The encryption key is associated and stored.
[0095] In the key setting system 104 in the second data protection system, the key information generation unit 302 constructs four quadtree tree structures as shown in FIG. 17, and all the leaves in the four tree structures are constructed. Each is associated with each of the decoding devices 103a to 103n. Therefore, there are four routes 1301-1304, and each decoding device corresponds to one of the tree-structured leaves.
[0096] FIG. 17 is a diagram showing an example of a tree structure of four quadtrees constructed when the number of decoding devices is 64 in the second data protection system according to the second embodiment. In this case, the tree structure of four quadtrees is constructed so that there are 64 leaves, so the lowest layer is level 2. For example, a decryption key group assigned to the terminal 1 shown in FIG. 17 by the key assignment process of the decryption key determination unit 305 in the second data protection system (see FIG. 10), and finally held in the terminal 1. Is the first of the decryption keys 2-1K assigned to the level 2 relative number 1 leaf and the decryption key assigned to the level 1 relative number 1 node that is the parent node of that leaf. Decryption keys corresponding to the invalidation pattern indicating that the child node is not an invalid node, namely "0000", "0001", "0010", "0011", "0100", "0101" and "0110" Seven decryption keys 1-1K0000, 1-1K0001, 1-1K0010, 1-1K0011, 1-1K0100, 1-1K0101 and 1-1K0110 corresponding to the conversion pattern, and level 0, which is the parent node one layer above it. Of the decryption keys assigned for the node with relative number 1 or route 1301, the seven decryption keys 0-1K0000, 0-1K0001, 0 corresponding to the invalidation pattern indicating that the first child node is not an invalid node. A total of 15 decryption keys including -1K0010, 0-1K0011, 0-1K0100, 0-1K0101 and 0-1K0110.
[0097] Further, for example, the decryption key assigned to the terminal 17 shown in FIG. 17 by the decryption key determination unit 305 in the second data protection system and held in the terminal 17 is the level 2 relative number 17. Indicates that the decryption key 2-17K assigned to the leaf and the decryption key assigned to the level 1 relative number 5 node that is the parent node of the leaf, the first child node is not an invalid node. Decryption keys corresponding to invalidation patterns, that is, 7 decryption keys corresponding to 7 invalidation patterns "0000", "0001", "0010", "0011", "0100", "0101" and "0110" 1-5K0000, 1-5K0001, 1-5K0010, 1-5K0011, 1-5K0100, 1-5K0101 and 1-5K0110, and the node with relative number 1 of level 0, which is the parent node one layer above it, that is, route 1302. Of the decryption keys assigned for, the seven decryption keys corresponding to the invalidation pattern indicating that the first child node is not an invalid node 0-2K0000, 0-2K0001, 0-2K0010, 0-2K0011, 0- A total of 15 decryption keys including 2K0100, 0-2K0101 and 0-2K0110.
Further, as shown in FIG. 17, it is specified by the encryption key identification unit 306 in the second data protection system in the absence of the invalidation terminal (see FIG. 13), is set in the encryption device 101, and is set to the optical disk 102. The encryption keys used when encrypting and recording the content key are the four encryption keys 0-1K0000, 0-2K0000, 0-3K0000 and 0-4K0000.
[0099] FIG. 18 is a diagram showing an encryption key or the like in a state where the terminal 1 is an invalidated terminal in the second data protection system. If only terminal 1 is an invalidation terminal, as a result of the invalidation information update process (see FIG. 12), the key information stored in the key information storage unit 301 is the node with the relative number 1 of the level 1 layer. The invalidation information of 1405 becomes "1000", the invalidation information of root 1401 of the level 0 layer becomes "1000", and it is encrypted by the key identification process (see FIG. 13) executed by the encryption key identification unit 306. The encryption keys specified as those to be set in the device 101 are the five encryption keys 0-1K1000, 1-1K1000, 0-2K0000, 0-3K0000 and 0-4K0000.
[0100] The operations of the encryption device 101 and the decryption devices 103a to 103n in the second data protection system are the same as the operations of the corresponding devices in the data protection system 100 shown in the first embodiment. <Embodiment 3> Hereinafter, the data protection system (hereinafter, referred to as third data protection system) according to the third embodiment of the present invention will be described with reference to the drawings.
[0101] The third data protection system is characterized in that it uses an invalidation pattern having contents different from the invalidation patterns shown in the first and second embodiments, but the other points are basically the data protection system 100. No change. The third data protection system includes basically the same components (see FIGS. 1 to 3) as the data protection system 100 shown in the first embodiment. Therefore, here, the components of the third data protection system will also be described using the reference numerals shown in FIGS. 1 to 3. Here, the third data protection system will be mainly described in terms of differences from the data protection system 100, and the same points will be omitted.
[0102] The key information storage unit 301 in the third data protection system is associated with five sets of decryption keys and encryption keys together with an invalidation pattern for each node other than the lowest layer, and each node in the lowest layer. Is stored in association with a set of decryption key and encryption key. However, in the first and second embodiments, the number of "1" among the values such as "0000" and "1000" that can be invalidated information about a certain node is the tree structure of the n-branch tree. The value of less than (n-1) is referred to as the invalidation pattern, but the invalidation pattern in the third embodiment is "1" among the possible values of the invalidation information for a certain node. It means each value that the number is less than 2.
Therefore, there are five types of invalidation patterns, "0000", "0001", "0010", "0100", and "1000", and the key information generation unit 302 allows each node other than the leaf to have five types of invalidation patterns. Five sets of encryption keys and decryption keys for all invalidation patterns are associated with each other, and key information in which one set of encryption keys and decryption keys is associated with each other is generated in the leaf, and the key information storage unit 301 is used. It is stored.
[0104] FIG. 19 is a diagram showing a decryption key assigned to each node in the quadtree tree structure used in the third embodiment. As shown in the figure, for example, the root is assigned five decryption keys of 0-1K0000, 0-1K0001, 0-1K0010, 0-1K0100 and 0-1K1000, and the node with relative number 1 of level 1 is assigned. Is assigned five decryption keys: 1-1K0000, 1-1K0001, 1-1K0010, 1-1K0100 and 1-1K1000.
[0105] Hereinafter, the operation of the third data protection system will be described by taking the case where there are only 64 decoding devices as an example. FIG. 20 is a diagram showing a decoding key group 1705 assigned to the decoding device (terminal 1) corresponding to the leaf of the relative number 1 of level 3 when it is assumed that there are only 64 decoding devices.
[0106] The decryption key assigned to the terminal 1 shown in FIG. 20 by the key assignment process (see FIG. 10) of the decryption key determination unit 305 in the third data protection system, and finally held in the terminal 1. Group 1705 is of the decryption key 3-1K assigned to leaf 1704 with relative number 1 of level 3 and the decryption key assigned to node 1703 with relative number 1 of level 2 which is the parent node of that leaf. , Decryption key corresponding to the invalidation pattern indicating that the first child node is not an invalid node, that is, four decodings corresponding to the four invalidation patterns "0000", "0001", "0010" and "0100". The first child of the decryption keys assigned to the keys 2-1K0000, 2-1K0001, 2-1K0010 and 2-1K0100 and the level 1 relative number 1 node 1702, which is the parent node one layer above it. Four decryption keys 1-1K0000, 1-1K0001, 1-1K0010 and 1-1K0100 corresponding to the invalidation pattern indicating that the node is not an invalid node, and the relative number of level 0, which is the parent node one layer above it. Of the decryption keys assigned for one node or root 1701, the four decryption keys 0-1K0000, 0-1K0001, 0-1K0010 and correspond to the invalidation pattern indicating that the first child node is not an invalid node. A total of 13 decryption keys with 0-1K0100. Therefore, according to the third data protection system, the number of decryption keys held by each terminal in the data protection system 100 shown in the first embodiment can be reduced.
The decryption key group assigned to each terminal by the decryption key determination unit 305 is stored in the decryption key group storage unit 212 of each terminal in the manufacturing process of each terminal or the like. Hereinafter, the encryption key required for recording the contents and the like on the optical disk 102 at the operation stage of the third data protection system will be described. Assuming that there are only 64 decryption devices, in the state where there is no invalidation terminal, the encryption key group of the encryption device 101 is identified by the key identification process of the encryption key identification unit 306 in the third data protection system. The encryption key stored in the storage unit 203 and used for encrypting the content key when recording the content on the optical disk 102 is an encryption key 0-1K0000, that is, one encryption corresponding to the decryption key 0-1K0000. It becomes the key to encryption.
[0108] FIG. 21 is a diagram showing an encryption key and the like in a state where terminals 1, terminal 2 and terminal 17 are invalidated terminals, assuming that there are only 64 decryption devices. The key information in the key information storage unit 301 is updated by the invalidation information update process of the key information update unit 304 in the third data protection system (see FIG. 12). The invalidation information update process is exactly the same as the content performed by the key information update unit 304 of the data protection system 100 shown in the first embodiment. As a result, regarding the key information stored in the key information storage unit 301, the invalidation information for the leaves of the relative numbers 1, 2, and 17 of the level 3 layer becomes "1111", and the level 2 layer. The invalidation information of node 1806 with relative number 1 is "1100", the invalidation information of node 1807 with relative number 5 of level 2 layer is "1000", and the invalidation information of relative number 1 of level 1 layer is. The invalidation information of node 1802 becomes "1000", the invalidation information of node 1803 with the relative number 2 of the level 1 layer becomes "1000", and the invalidation information of root 1801 of the level 0 layer becomes "1100". , The invalidation information of other nodes is "0000". The node whose corresponding invalidation information is "0000" is a valid node, and the other nodes are invalid nodes.
[0109] Following the invalidation information update process, the encryption key is specified by the key identification process (see FIG. 13) of the encryption key identification unit 306. Hereinafter, the specific processing content of the key identification process based on the example shown in FIG. 21 will be described with reference to FIG. In this example, the lowest layer is level 3.
[0110] First, the encryption key identification unit 306 pays attention to the uppermost node, that is, the route 1801 (step S31). Subsequently, the encryption key identification unit 306 refers to the key information stored in the key information storage unit 301 for the node 1801 of interest, and the invalidation information "1100" of the node 1801 is described above. It is determined whether it matches any of the five types of invalidation patterns (step S32), and since it does not match any of them, it is determined whether the layer one layer below the node 1801 of interest is the lowest layer. Judgment (step S36), since the layer one layer below the node 1801 of interest is the level 1 layer and not the lowest layer, all the child nodes of node 1801 are defined as the nodes to be focused on (step S38). ).
[0111] According to this step S38, the nodes 1802 to 1805 become the nodes to be focused on. Subsequently, the encryption key identification unit 306 determines whether or not there is an unfocused target node (step S39), and since there is an unfocused target, pays attention to one of them, node 1802 (step S40). , Returning to the determination process of step S32, referring to the key information, it is determined whether the invalidation information "1000" of the node 1802 of interest matches any of the above-mentioned five types of invalidation patterns. (Step S32), and since it matches, specify the encryption key 1-1K1000 corresponding to the invalidation pattern "1000" for node 1802 as the encryption key to be set in the encryption device 101 (step S33), and pay attention to it. Since the layer one layer below the node 1802 is the level 2 layer and not the lowest layer (step S34), the invalid node 1806 among the child nodes of the node 1802 is defined as the node to be focused on (step S35). ).
[0112] After step S35, the encryption key identification unit 306 determines whether or not there is an unfocused target node (step S39), and since there is an unfocused attention schedule, pays attention to one of them, node 1806. Then (step S40), the process returns to the determination process of step S32. Next, the encryption key identification unit 306 refers to the key information and determines whether the invalidation information "1100" of the node 1806 matches any of the above-mentioned five types of invalidation patterns (step S32). ), Since neither of them matches, it is determined whether the layer one layer below the node 1806 of interest is the lowest layer (step S36), and the layer one layer below the node 1806 is level 3. Since it is the lowest layer and the lowest layer, the encryption key 3-3K and the encryption key 3-4K corresponding to the effective nodes leaf 1808 and 1809 of the child nodes of the node 1806 are used in the encryption device 101. Identify it as the encryption key to be set in (step S37), determine if there is an unfocused planned node (step S39), and since there is an unfocused planned target, pay attention to one of them, node 1803. (Step S40), the process returns to the determination process of step S32.
Next, the encryption key identification unit 306 determines whether the invalidation information "1000" of the node 1803 matches any of the above-mentioned five types of invalidation patterns by referring to the key information. (Step S32) Since it matches, specify the encryption key 1-2K1000 corresponding to the invalidation pattern "1000" for node 1803 as the encryption key to be set in the encryption device 101 (step S33), and pay attention to it. Since the layer one layer below the existing node 1803 is the level 2 layer and not the lowest layer (step S34), node 1807, which is an invalid node among the child nodes of node 1803, is defined as the planned node (step S35). ..
[0114] Subsequently, the encryption key identification unit 306 determines whether or not there is an unfocused target node (step S39), and since there is an unfocused attention schedule, pays attention to one of them, node 1807 (step S39). Returning to the determination process of step S40) and step S32, referring to the key information, the invalidation information "1000" of the node 1807 of interest matches any of the above-mentioned five types of invalidation patterns. (Step S32), and since it matches, the encryption key 2-5K1000 corresponding to the invalidation pattern "1000" for node 1807 is specified as the encryption key to be set in the encryption device 101 (step S33). Since the layer one layer below the node 1807 of interest is the level 3 layer and the lowest layer (step S34), the processing of step S35 is skipped and it is determined whether there is an unfocused node to be focused on. Then (step S39), since there is an unfocused attention schedule, focus on one of them, node 1804 (step S40), and return to the determination process of step S32.
Next, the encryption key identification unit 306 refers to the key information, and the invalidation information "0000" of the node 1804 of interest matches any of the above-mentioned five types of invalidation patterns. It is determined whether or not to be performed (step S32), and since it matches, the encryption key 1-3K0000 corresponding to the invalidation pattern "0000" for the node 1804 is specified as the encryption key to be set in the encryption device 101 (step S33). ) Therefore, since the layer one layer below the node 1804 of interest is the level 2 layer and not the lowest layer (step S34), the invalid node among the child nodes of the node 1804 is defined as the node to be focused on. (Step S35). However, since all the child nodes of node 1804 are valid nodes, a new node to be focused on cannot be determined.
[0116] Subsequently, the encryption key identification unit 306 determines whether or not there is a node of interest that has not been focused (step S39), focuses on node 1805 that is a node of interest that has not been focused (step S40), and steps S32. Returning to the determination process of, and referring to the key information, it is determined whether the invalidation information "0000" of the node 1805 of interest matches any of the above-mentioned five types of invalidation patterns (step S32). ), Since it matches, the encryption key 1-4K0000 corresponding to the invalidation pattern "0000" for the node 1805 is specified as the encryption key to be set in the encryption device 101 (step S33), and the node 1805 of interest is selected. Since the layer one layer below is the level 2 layer and not the lowest layer (step S34), the invalid node among the child nodes of node 1805 is defined as the node to be focused on (step S35). However, since all the child nodes of node 1805 are valid nodes, no new node to be focused on can be determined.
[0117] Subsequently, the encryption key identification unit 306 determines whether or not there is a node of interest that has not been focused (step S39), and since there is no node of interest that has not been focused anymore, the key identification process is completed. As a result of such key identification processing, the encryption keys identified as those to be set in the encryption device 101 are the encryption keys 1-1K1000, 1-2K1000, 1-3K0000, 1-4K0000, 2-5K1000, There are 7 keys, 3-3K and 3-4K.
[0118] These seven encryption keys are later stored in the encryption key group storage unit 203 of the encryption device 101, and are used by the key encryption unit 204 for encrypting the content key. In addition, each encrypted content key generated by encryption using each encryption key can be used by the output unit 206 to specify the decryption key corresponding to each encryption key, and the key identification information and encryption. It will be recorded on the optical disk 102 together with the encrypted content.
[0119] As a result of assigning the decryption key to each terminal by the decryption key determination unit 305 described above, all the decryption keys corresponding to the seven encryption keys are held in the terminal 1, the terminal 2, or the terminal 7. In addition, one or more of the decryption keys corresponding to these seven encryption keys are held in the other terminals. Therefore, after the content is recorded on the optical disk 102 by the encryption process using these seven encryption keys, it is recorded on the optical disk 102 using the decryption keys exposed from the terminals 1, the terminal 2, and the terminal 7. The decryption process of the content cannot be normally performed, and the decryption process of the content recorded on the optical disk 102 can be normally performed on another terminal. <Embodiment 4> Hereinafter, the data protection system (hereinafter, referred to as fourth data protection system) according to the fourth embodiment of the present invention will be described with reference to the drawings.
[0120] In the data protection system 100 shown in the first embodiment, the optical disk 102 for the encryption device 101 to record the encrypted content and distribute it to the decryption devices 103a to 103n is a DVD-ROM or the like. However, the 4th data protection system assumes only the recordable media when the optical disk 102 is divided into so-called pre-recorded media such as DVD-ROM and so-called recordable media such as DVD-RAM. This is an embodiment of the above.
That is, the fourth data protection system records certain information on the system side of the optical disc 102, which is a recordable medium, and the user encrypts arbitrary contents on the optical disc 102 by the terminal. It is a system that can be converted and recorded to distribute the optical disc 102, and that the user can decode and use the content recorded on the optical disc 102 on the same or different terminals. Here, the fourth data protection system will be mainly described in terms of differences from the data protection system 100, and the same points will be omitted.
[0122] FIG. 22 is a schematic configuration diagram of a fourth data protection system according to a fourth embodiment of the present invention. As shown in the figure, the fourth data protection system includes a key identification information recording device 1501, a plurality of user data encryption devices (terminals) 1502a to 1502n, a plurality of decryption devices (terminals) 103a to 103n, and a key setting system 104. To be equipped. For example, it is assumed that the key setting system 104 and the key identification information recording device 1501 are operated by an organization that manages copyright protection, and each terminal is used by general users.
The decryption devices 103a to 103n are the same as those shown in the first embodiment, and all or part of the user data encryption devices 1502a to 1502n are all or part of the decryption devices 103a to 103n. It may be implemented in the same terminal as. Further, the key setting system 104 in the fourth data protection system is basically the same as that shown in the first embodiment, but there are some additional functions. That is, the key setting system 104 in the fourth data protection system presupposes the construction of a quadrant tree structure in which each terminal corresponds to a leaf in advance, and performs the decryption key group to each terminal by the key allocation process shown in FIG. At this time, if the terminal to be assigned is a decryption device, a decryption key group is assigned, and if the terminal to be assigned is a user data encryption device, an encryption key group corresponding to the decryption key group is assigned. And. The key setting system 104 generates and outputs information indicating the correspondence between the key assigned to each terminal and the node in the tree structure.
[0124] In the fourth embodiment, for convenience, it is assumed that the user data encryption devices 1502a to 1502n are mounted on the same terminal as the decryption devices 103a to 103n, respectively, and the corresponding encryption key is used. The decryption key will be described as having the same value. Therefore, each terminal is provided with a key group which is a decryption key group and an encryption key group assigned by the key setting system 104 in advance, and information indicating the correspondence between each key and a node in the tree structure. Get from 104 and hold.
[0125] Further, the key setting system 104 in the fourth data protection system is further specified in the operation stage as a result of the invalidation information update process (see FIG. 12) and the key identification process (see FIG. 13). It has a function to output the key identification information (see FIG. 16) indicating the encryption key to the key identification information recording device 1501. For example, in the state where there is no invalidation terminal, the key identification information is only "0-1K0000".
[0126] The key identification information recording device 1501 is a device including hardware capable of recording data on an optical disk and having a function of recording the key identification information input from the key setting system 104 on the optical disk 102. Further, each of the user data encryption devices 1502a to 1502n has a function corresponding to each function of the encryption device 101 (see FIG. 2) shown in the first embodiment. However, the user can freely store digital contents in the content storage unit 201, and the contents of the encryption key group storage unit 203 are obtained from the above-mentioned key setting system 104 and held by the terminal. The key group and information indicating the correspondence between each encryption key and the node in the tree structure, and the encryption key used by the key encryption unit 204 to encrypt the content key acquired from the random number generation unit 202 will be described later. It was selected as a result of the encryption key selection process, and the output unit 206 does not record the key identification information on the optical disk 102, but records the encrypted content and the encrypted content key on the optical disk 102.
[0127] Further, each of the user data encryption devices 1502a to 1502n further reads the key identification information recorded by the key identification information recording device 1501 from the optical disk 102 and selects an encryption key to be used for encrypting the content key. It has a function to perform encryption key selection processing. In this encryption key selection process, the information indicating the correspondence between each encryption key and the node in the encryption key group storage unit 203 is collated with the key identification information, and if there is a content indicating the same node in both, the information is displayed. This is a process of selecting the encryption key corresponding to the node and sending it to the key encryption unit 204, which is the same as the process of selecting the decryption key in the decryption key selection unit 213 in the decryption device 103a shown in the first embodiment. It is a process.
[0128] That is, when each of the user data encryption devices 1502a to 1502n encrypts and records the content on the optical disk 102 with the content key, the encryption key according to the key specific information recorded in advance in the optical disk 102. It is a device having a function of encrypting a content key using the above and recording the content key on the optical disk 102. Therefore, according to this fourth data protection system, many terminals other than the terminal whose decryption key or the like is exposed due to unauthorized analysis cannot be correctly decrypted by the exposed decryption key and are exposed. Many terminals with no decryption key will be able to encrypt the content and record it on the optical disk 102 so that it can be correctly decrypted and used. <Supplement> The data protection system according to the present invention has been described above based on the first to fourth embodiments, but it goes without saying that the present invention is not limited to these embodiments. That is, although it was decided that the contents shown in (1) Embodiments 1 to 4 are video, audio, etc., the contents of the contents are not limited to these, and even if it is a program or other data, these are May be a combination of video and the like. (2) The decoding device shown in the first to fourth embodiments is provided with a playback unit 216 for reproducing the decoded content, but instead, it may have a function of outputting the decoded content to the outside of the device. Good. (3) In the first to third embodiments, the encrypted contents and the like are recorded on the optical disk 102 and distributed to each decryption device. However, the encrypted contents and the like are distributed to each decryption device as a recording medium. In addition to the distribution by, it may be distributed through a wireless or wired transmission line.
[0129] In the case of adopting the form of distributing the encrypted content or the like, the output unit 206 of the encryption device 101 shall be provided with hardware having a communication function, and the encrypted content, the encrypted content key, and the key identification shall be provided. It is necessary to transmit information to each decryption device (terminal), and the acquisition unit 211 such as the decryption device 103a shall be equipped with hardware having a communication function, and shall be equipped with encrypted content, encrypted content key, and key identification. It is necessary to receive and obtain the information. As a distribution method, for example, the encryption device 101 may record on a recording medium in a server connected to the Internet, and the decryption device 103a or the like may receive the contents of the recording medium via the Internet.
[0130] Further, the recording medium in the case of adopting the form of recording and distributing the encrypted content or the like on the recording medium is not limited to the optical disc, but may be an IC card, a flexible disk, a magnetic tape, a ROM, or the like. May be good. (4) The method of defining the invalidation pattern corresponding to each node in the key information shown in the first embodiment is just an example, and for example, each node other than the root does not have the invalidation pattern of "0000". , Each node other than the leaf has the invalidation pattern of "0111", "1101", "1011", "1110", and the key allocation process (see Fig. 10) and key identification process (Fig. 13) are matched accordingly. The contents of (see) may be changed slightly.
[0131] Further, in the first embodiment, the invalidation pattern and the like are defined on the premise of constructing a quadtree tree structure, but the premise tree structure is an n-tree tree structure in which n is 3 or more. It may be a tree structure that includes at least a part of the tree, that is, a tree structure in which one node in at least one layer is a parent node of three or more child nodes. It is also possible to use a tree structure in which a ternary tree, a quadtree, or the like is different in each layer.
[0132] Further, in the first embodiment, the invalidation pattern for each node of the quadtree tree structure is limited to the one in which the number of "1" is less than 3, and in the third embodiment, four minutes. The invalidation pattern for each node of the tree structure is limited to those with less than 2 "1" s, but for example, the invalidation pattern for each node of the quadtree tree structure is "1". The number may be limited to less than 2, less than 3, or less than 4. (5) Each part related to decryption in the decryption devices 103a to 103n shown in the first to fourth embodiments and each part related to encryption in the user data encryption devices 1502a to 1502n shown in the fourth embodiment are so-called resistant. It is desirable that the tamper technology be configured to protect the methods and data used for decryption or encryption. (6) In the first embodiment, when the key setting system determines the decryption key to be assigned to each terminal, the decryption key and the information indicating the node in the tree structure to which the decryption key corresponds are output, and as a result, the decryption key is output. The decryption devices 103a to 103n have decided to hold the decryption key group and the information indicating the node corresponding to each decryption key, but the decryption device does not necessarily have to hold the information indicating the node corresponding to the decryption key. .. When the information indicating the node corresponding to the decryption key is not retained, the decryption device attempts to decrypt the encrypted content key recorded on the optical disk by sequentially using each decryption key held by the decryption device. The key may be decrypted. In this case, a rule such as the first 8 bits being 0 is set in advance for the content key, and the validity of the decrypted content key can be confirmed by using a general digital signature or the like. As a matter of fact, the decryption device may decrypt the content using the decrypted content key only when the decrypted content key is valid. (7) In the first embodiment, the content key, the decryption key, and the encryption key are set to 64 bits, but the data size of the key is not limited to 64 bits, and may be other bits. May be good. In FIG. 16, it was decided that the key identification information includes a character string that is a combination of a character string that is a node ID, the character "K", and a character string of an invalidation pattern, but the format of the key identification information is It is not limited to this. (8) In the first to fourth embodiments, the content key used for content encryption is the target of encryption using the encryption key represented by 0-1K0000 or the like, but the target of encryption is It is not limited to the content key, and may be any data that requires confidentiality. (9) Executing the invalidation information update process, key allocation process, or key identification process (procedure shown in FIG. 10, FIG. 12 or FIG. 13) in the key setting system 104 shown in the first to fourth embodiments by a computer or a program. A computer program to be executed by a device having a function can be recorded on a recording medium or distributed and distributed via various communication paths or the like. Such recording media include IC cards, optical discs, flexible disks, ROMs, and the like. The distributed and distributed computer programs are used by being installed on a computer or the like, and the computer or the like is executed by executing the computer program to perform invalidation information update processing and key allocation processing as shown in the first to fourth embodiments. Alternatively, perform key identification processing. The computer program can also be recorded on a recording medium or distributed and distributed via various communication paths and the like. Such recording media include IC cards, optical discs, flexible disks, ROMs, and the like. The distributed and distributed computer programs are used by being installed on a computer or the like, and the computer or the like is executed by executing the computer program to perform invalidation information update processing and key allocation processing as shown in the first to fourth embodiments. Alternatively, perform key identification processing. The computer program can also be recorded on a recording medium or distributed and distributed via various communication paths and the like. Such recording media include IC cards, optical discs, flexible disks, ROMs, and the like. The distributed and distributed computer programs are used by being installed on a computer or the like, and the computer or the like is executed by executing the computer program to perform invalidation information update processing and key allocation processing as shown in the first to fourth embodiments. Alternatively, perform key identification processing.
[Effect of the Invention] As is clear from the above description, the data protection system according to the present invention includes three or more terminals, an encryption device, and an encryption key identification device, and is distributed to each terminal. A data protection system that protects data by encrypting it with an encryption device. Each terminal stores a decryption key group individually assigned by a predetermined key allocation method, and is output from the encryption device. The encrypted distribution data group is acquired and the encrypted distribution data is decrypted by using the stored decryption key. The predetermined key allocation method is as follows: (a) Each terminal has 2 A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets which are a set including one or more terminals in the element, and in the plurality of terminal sets. Two or more terminal sets are determined so that there is a plurality of terminal sets in which the relation that none of the terminal sets is a subset of each other terminal set in the plurality of terminal sets is established. (b) Determine a separate decryption key for each terminal and each determined terminal set, and (c) This is a method of assigning a decryption key determined corresponding to the terminal and a decryption key defined corresponding to each of all the terminal sets including the terminal to the terminal, and is a method of assigning the encryption key specifying device. Is a device that identifies an encryption key, and is a means for identifying an invalidation terminal that identifies one or more terminals as an invalidation terminal, and among all decryption keys assigned to the terminals by the predetermined key allocation method. When a decryption key other than the decryption key assigned to the invalidation terminal is defined as the valid decryption key, the valid decryption key assigned to the most terminals to which the selected valid decryption key is not assigned is selected. Assuming that the procedure is repeated until there are no terminals to which the selected valid decryption key is assigned, specify the encryption key corresponding to each of the selected valid decryption keys as a result. It is a device having an encryption key identification means, and the encryption device encrypts distribution data by sequentially using all the encryption keys specified by the encryption key identification device, and encrypts the distribution data group. It is characterized by having an encryption means for generating and outputting.
[0134] Here, the distribution data is data that is expected to be recorded and distributed on a recording medium, or distributed through a wired or wireless communication path, and finally reach each terminal. Assuming terminal 1, terminal 2, and terminal 3, the terminal set determined by the above-mentioned predetermined key allocation method includes a set A of terminal 1 and terminal 2, a set B of terminal 1 and terminal 3, and a terminal 2. And there is a set C of the terminal 3, and the decryption key stored and held by the terminal 1 in response to the allocation result by the predetermined key allocation method corresponds to the decryption key unique to the terminal 1, the decryption key A corresponding to the set A, and the set B. The decryption key B stored in the terminal 2 is the decryption key unique to the terminal 2, the decryption key A corresponding to the group A, and the decryption key C corresponding to the group C. The decryption keys to be stored and held are the decryption key unique to the terminal 3, the decryption key B corresponding to the set B, and the decryption key C corresponding to the set C. In this example, if the terminal 2 is illegally analyzed and all the decryption keys stored and held by the terminal 2 are exposed, the terminal 2 is specified as an invalidation terminal, that is, a terminal to be invalidated. When the encryption key is specified by the encryption key specifying means, the encryption key corresponding to the decryption key B is specified.
Therefore, if the data is encrypted using the encryption key corresponding to the decryption key B and distributed to each terminal, the data cannot be correctly decrypted on the terminal 2 and correctly on the terminal 1 and the terminal 3. The data can be decrypted. For the same purpose, data can be encrypted and distributed to each terminal by using an encryption key corresponding to the decryption key unique to terminal 1 and an encryption key corresponding to the decryption key unique to terminal 3. Compared to this method, the method using the encryption key corresponding to the decryption key B described above has the effect that the number of encryption keys used for encryption is small and the amount of encrypted data to be distributed is reduced accordingly. Has.
That is, according to the present invention, in a data protection system that encrypts data such as a key required for decrypting encrypted digital contents and distributes the same data to a plurality of terminals, the encrypted data to be distributed If the decryption key held by a specific terminal is exposed by an unauthorized person after suppressing the increase in the amount, the specific terminal cannot correctly decrypt the data and other terminals. Allows the data to be decrypted correctly.
[0137] Further, the predetermined key allocation method is a plurality of terminal sets each including the same one or more terminal sets so that there is a terminal set completely including the plurality of terminal sets. Therefore, the terminal set is such that there is a plurality of terminal sets in which the relationship that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets is established. It may be a method of making the above determination.
[0138] For example, when the decryption key AB is associated with the terminal set AB including the terminal set A and the terminal set B, and the decryption key BC is associated with the terminal set BC including the terminal set B and the terminal set C. In this data protection system, at least the decryption key AB is assigned and stored, but the decryption key BC is assigned to the terminals belonging to the terminal set A but not belonging to the terminal set B or the terminal set C. At least the decryption key BC is assigned to the terminals belonging to the terminal set B or the terminal set C without being stored and stored. Therefore, even after a terminal belonging to the terminal set A but not belonging to the terminal set B or the terminal set C is illegally analyzed, the data is encrypted using at least an encryption key corresponding to the decryption key BC. By distributing to each terminal, the terminal group included in the terminal set BC, that is, the terminal group included in the terminal set B and the terminal group included in the terminal set C correctly decode the data using the decryption key BC. It becomes possible to encrypt data so that it can be correctly decrypted by many terminals using a small number of encryption keys.
[0139] Further, the predetermined key allocation method further comprises a terminal set so that each terminal set includes three or more terminals as an element and there is a terminal set including three or more terminal sets. May be the method of making the above determination. As a result, when distributing the same encrypted data to each terminal, encryption using a key common to three or more terminals can be performed, so the data to be distributed is more than when different keys are used for each. You will be able to reduce the amount.
[0140] Further, the data protection system is the lowest in the case of assuming a tree structure of a plurality of layers of N-branches (N is a natural number of 3 or more) in which each terminal corresponds to a separate node of the lowest layer. For each node excluding the layer, out of the N nodes in the lower layer of the 1st stage that can be reached from the node (parent node), 2 or more are combined to determine and determine a plurality of combination patterns including all N combinations. A separate decryption key is determined for each combination pattern, and each of the determined decryption keys is stored in association with the relevant node (parent node), and a separate decryption key is associated with each node in the lowest layer. A storage device and a device that executes the predetermined key allocation method and determines a decryption key group to be assigned to each terminal, and for each terminal, a node of the lowest layer corresponding to the terminal. For each node that is not the lowest layer located on the path from the node to the highest layer node, among the decryption keys stored by the key storage device in association with the node, the node is one step lower layer of the node. The decryption key corresponding to all the combination patterns related to the combination including the node located on the route and the decryption key stored by the key storage device in association with the terminal should be assigned to the terminal. Each terminal set has a one-to-one correspondence with each combination pattern, and all corresponding to the lowest layer node reached from all the combined nodes in the corresponding combination pattern. It corresponds to a set having the terminal of the above as an element, and the encryption key specifying means reaches all the nodes of the lowest layer corresponding to any of the invalidated terminals in the case of assuming the tree structure. The node is defined as an invalid node, the highest layer node is first set as the processing target node, the encryption key identification process is repeated until there are no unprocessed processing target nodes, and the encryption key identification process is unprocessed. For one processing target node, (a)If the combination pattern related to the combination including all the nodes other than the invalid node exists in the one-stage lower layer of the processing target node, the decryption key stored in the key storage device corresponding to the combination pattern. (B) If the combination pattern related to the combination including all nodes other than the invalid node does not exist in the lower layer of the 1st stage of the processing target node, the encryption key corresponding to the above is not present. If is the lowest layer, the encryption key corresponding to the decryption key stored in the key storage device corresponding to all the nodes other than the invalid node in the one-stage lower layer is specified, and the one-stage lower layer is concerned. If is not the lowest layer, all nodes other than the invalid node in the lower layer of the first stage are newly set as the processing target node, and (c) if there is an invalid node in the lower layer of the first stage of the processing target node, the 1 Unless the stage layer is the lowest layer, it may be a process in which all invalid nodes are newly set as the processing target nodes.
[0141] In this way, information such as a decryption key is associated with each node in the tree structure, and a decryption key to be assigned to each terminal is determined based on the information and the position of each node in the tree structure, and distribution data. By the method of specifying the encryption key used for the encryption of the above-mentioned purpose, that is, the increase in the amount of encrypted data to be distributed is suppressed, and then the terminal can be analyzed by the analysis of the specific terminal or the like. When the held decryption key is exposed by an unauthorized person, it is possible to realize a system that achieves the purpose of enabling the specific terminal to correctly decrypt the data and the other terminal to correctly decrypt the data.
[0142] Further, the determination of the plurality of combination patterns for each node other than the lowest layer in the case of assuming the tree structure by the key storage device is one step lower layer reached from the node (parent node). This is done by defining a combination pattern so as to correspond to each combination of two or more of the N nodes in the above, and the key storage device determines a separate decryption key for each determined combination pattern. Each of the determined decryption keys may be stored in association with the node (parent node).
[0143] As a result, the number of the specified encryption keys is kept small in the method of specifying the encryption key used for encrypting the distribution data to each terminal by using the tree structure of the n-branch tree. As a result, it is possible to keep the amount of encrypted distribution data distributed to each terminal relatively small. Further, the key storage device determines the plurality of combination patterns for each node excluding the lowest layer in the case of assuming the tree structure, and N pieces of the one-stage lower layer arriving from the node (parent node). It is made by defining a combination pattern so as to correspond to each of all N combinations and (N-1) all combinations among the nodes of the above, and the key storage device is separate for each determined combination pattern. A decryption key may be determined and each of the determined decryption keys may be stored in association with the node (parent node).
[0144] Thereby, in the method of specifying the encryption key used for encrypting the distribution data to each terminal using the tree structure of the n-branch tree, the number of decryption keys assigned to each terminal is compared. As a result, the amount of data in the decryption key group stored and held by each terminal can be kept relatively small. Further, the encryption means uses the encryption distribution data generated by encryption using the encryption key and the key storage device for each of the encryption keys specified by the encryption key identification device. The decryption key corresponding to the encryption key and the encryption key node identification information for specifying the location of the node in the tree structure associated with the encryption key are output in association with each other, and each terminal has a predetermined key. Each decryption key individually assigned by the allocation method is stored in association with the decryption key node identification information for identifying the location of the node associated with the decryption key in the tree structure by the key storage device. The encryption key node that matches the decryption key node identification information stored in the terminal by acquiring the encryption distribution data group and the encryption key node identification information group output from the encryption device. The encrypted distribution data corresponding to the identification information may be decrypted by using the decryption key corresponding to the decryption key node identification information related to the match.
[0145] As a result, each terminal acquires the encrypted distribution data group in which the distribution data is encrypted by using one or more encryption keys, and then obtains the encryption key node identification information group. By referring to it, it becomes possible to easily specify which decryption key held by the own terminal should be used for decryption, and the decryption key held by the own terminal is sequentially used for decryption by trial and error. The time required for correct decryption is shortened compared to the case where it is performed.
[0146] Further, the encryption key specifying device has an encryption key storage means for storing an encryption key corresponding to each decryption key stored in the key storage device, and the corresponding decryption key. And the encryption key may be different from each other. As a result, even if the decryption key is exposed due to unauthorized analysis of a certain terminal, the encryption key for encrypting the data so that it can be correctly decrypted by multiple terminals is illegally known and misused. It will be possible to prevent the occurrence of such a situation.
[0147] Further, the output by the encryption means is to record the generated data group for encryption distribution on a data recording medium, and each terminal is a data group for encryption distribution by the encryption device. The encrypted distribution data group may be read and acquired from the data recording medium on which the data is recorded, and the encrypted distribution data may be decrypted. As a result, the data is encrypted and recorded on an optical disk such as a DVD-ROM or other recording medium. Therefore, for example, a recording medium having the same content as the recording medium can be mass-produced and distributed to a large number of people for a fee or free of charge. The person who receives the distributed recording medium can set the recording medium in the terminal and use the data recorded in the recording medium through the terminal.
[0148] Further, the encryption means is provided by a content storage unit that stores content data that is a digital work, a random number data generation unit that generates the distribution data that is a random number, and the random number data generation unit. It has a content encryption unit that encrypts the content data using the generated distribution data as a key to generate encrypted content data, and the encryption means is specified by the encryption key identification device. By encrypting the distribution data generated by the random number data generator by sequentially using all the encryption keys, an encrypted distribution data group is generated, and the encrypted distribution data group and the said The encrypted content data generated by the content encryption unit is recorded on the data recording medium, and each terminal reads and acquires the encrypted content data and the encrypted distribution data group from the data recording medium. The encrypted distribution data may be decrypted, and the encrypted content data may be decrypted using the distribution data that is the decryption result.
[0149] As a result, the key required for decrypting the digital content such as the encrypted video and audio is encrypted, and the encrypted digital content and the data including the encrypted key are recorded on the recording medium. , A recording medium having the same content as the recording medium is distributed to a large number of people, and the person who receives the distributed recording medium can set the recording medium in the terminal and play digital contents through the terminal. Will be.
[0150] Further, the data protection system further records an encryption key identification information for identifying an encryption key specified by the encryption key identification device on a data recording medium. Each terminal is provided with a random number data generation unit that generates the distribution data that is a random number, a content storage unit that stores content data that is a digital work, and an encryption key identification from the data recording medium. It has an encryption key selection unit that reads information and selects an encryption key specified by the encryption key specific information from among the encryption key groups that correspond to the decryption key group stored in the terminal. The encryption means generates an encrypted distribution data group by sequentially using all the encryption keys selected by the encryption key selection unit to encrypt the distribution data generated by the random number data generation unit. Then, the data is recorded on the data recording medium, and each terminal further encrypts the content data stored in the content storage unit by using the distribution data generated by the random number data generation unit as a key. The content encryption unit that generates encrypted content data and records the encrypted content data on the data recording medium, and each terminal uses the encrypted content data and the encrypted distribution data from the data recording medium. The group may be read and acquired, the encrypted distribution data may be decrypted, and the encrypted content data may be decrypted using the distribution data which is the decryption result.
[0151] As a result, in a system in which a terminal user can record and distribute arbitrary digital contents such as video and audio on a recording medium such as DVD-RAM, the terminal is analyzed by analysis of a specific terminal or the like. If the decryption key held by is exposed by a fraudulent person, it will be possible to encrypt the digital content so that the data cannot be decrypted correctly on that particular terminal and the data can be decrypted correctly on other terminals. ..
[0152] Further, the output by the encryption means is to transmit the generated data group for encryption distribution to each terminal, and each terminal transmits the encrypted distribution transmitted by the encryption device. The data group may be received and acquired, and the encrypted distribution data may be decrypted. As a result, the distribution data is encrypted and transmitted to each terminal, so that each terminal can easily use the distribution data by receiving the data.
[0153] Further, the decryption key determination device according to the present invention is for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. A decryption key determination device, (a) so that each of the terminals belongs to at least one of a set of terminals that includes two or more terminals as elements, and further, each of the same one or more terminals. A plurality of terminals included in an element, wherein any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets. Decryption key setting means that determines two or more terminal sets so that a set exists, and (b) associates a separate decryption key for each terminal and each determined terminal set, and for each terminal, the above. Decryption key group allocation that determines the decryption key associated with the terminal by the decryption key setting means and all the decryption keys associated with each of all the terminal sets including the terminal as the decryption key group to be assigned to the terminal. It may be provided with means.
[0154] Further, the decryption key determination method according to the present invention is for determining a decryption key group for decryption to be individually assigned to each of three or more terminals for acquiring and decrypting encrypted data. A method for determining a decryption key, such that each terminal belongs to at least one of a terminal set which is a set including two or more terminals in an element, and further includes the same one or more terminals in each element. There is a plurality of terminal sets in which the relationship that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets is established. As described above, a terminal set determination step for determining two or more terminal sets, a decryption key associating step for associating different decryption keys for each terminal and for each terminal set determined by the terminal set determination step, and the above. For each terminal, the decryption key associated with the terminal by the decryption key mapping step and all the decryption keys associated with each of all the terminal sets including the terminal are assigned to the terminal. It is characterized by including a decryption key group allocation step determined as a group.
[0155] Further, the decryption terminal system according to the present invention is a decryption terminal system composed of three or more terminals for acquiring and decrypting encrypted data, and each terminal is a predetermined key. Decryption key group storage means that stores decryption key groups individually assigned by the allocation method, encrypted data acquisition means that acquires encrypted data, and data acquired by the encrypted data acquisition means. A decryption means for decrypting using a decryption key stored in the decryption key group storage means is provided, and the predetermined key allocation method is as follows: (a) A set in which each terminal includes two or more terminals as elements. A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets, and any one terminal set in the plurality of terminal sets is the plurality of terminals. Two or more terminal sets are determined so that there is a plurality of terminal sets in which the relationship that the terminal set is not a subset of each other terminal set is established, and (b) each terminal and the determined terminal are determined. A separate decryption key is set for each set, and (c) The method is characterized in that a decryption key determined corresponding to the terminal and a decryption key determined corresponding to each of all the terminal sets including the terminal are assigned to each terminal.
[0156] Further, the decryption terminal according to the present invention is a decryption terminal for acquiring and decrypting encrypted data, and stores decryption key groups individually assigned by a predetermined key allocation method. A decryption key group storage means, an encrypted data acquisition means for acquiring encrypted data, and a decryption key stored in the decryption key group storage means for the data acquired by the encrypted data acquisition means are used. The decoding means and the predetermined key allocation method are as follows: (a) A plurality of terminals in which the terminal is a set including two or more terminals in the case of assuming three or more terminals including the terminal. As if it belongs to a set, it is a plurality of terminal sets each including the terminal as an element, and any one terminal set in the plurality of terminal sets is a subset of each other terminal set in the plurality of terminal sets. Determine two or more terminal sets so that there are multiple terminal sets where the relationship that is not established is established, and (b) separate each for the terminal and for each determined terminal set. (C) By assigning the decryption key specified for the terminal and the decryption key specified for each of all terminal sets including the terminal to the terminal. It is characterized by being.
[0157] As a result, for example, when the data of the result encrypted on the recording medium is recorded on each terminal and the recording medium is distributed, the increase in the amount of data recorded on the recording medium is suppressed. So, if the decryption key held by a specific terminal is exposed by an unauthorized person by analysis of a specific terminal, the data cannot be decrypted correctly on that specific terminal and the data can be decrypted correctly on other terminals. It becomes possible to carry out the encryption.
[0158] Further, the encrypted data acquisition means may read the encrypted data from the data recording medium and acquire the encrypted data. As a result, the encrypted data can be recorded on a data recording medium and the recording medium can be distributed to the users of each terminal so that the users of each terminal can use the data.
Further, the data recording medium records the encryption key identification information for specifying the encryption key, and the terminal further includes a random number data generating means for generating key data which is a random number. A content storage means for storing content data that is a digital work, and an encryption key that reads encryption key specific information from the data recording medium and corresponds to a decryption key group stored in the decryption key group storage means. The random number data generation means using the encryption key selection means for selecting the encryption key specified by the encryption key specific information in the group and all the encryption keys selected by the encryption key selection means sequentially. An encrypted key data group is generated by encrypting the key data generated by the above, and the encrypted key data group is recorded on the data recording medium. The key data encryption means and the random number data generation means generate the data. Encrypted content data is generated by encrypting the content data stored in the content storage unit using the key data as a key, and the encrypted content data is recorded in the data recording medium. The encrypted data acquisition means acquires the encryption key data and the encrypted content data recorded in the data recording medium, and the decryption means is acquired by the encryption data acquisition means. The key data is generated by decrypting the encryption key data using the decryption key stored in the decryption key group storage means, and the terminal is further acquired by the encryption data acquisition means. The encrypted content data may be provided with a content decryption means for decrypting the encrypted content data using the key data generated by the decryption means.
[0160] As a result, the user of each terminal can encrypt digital contents such as video and audio and record them on a recording medium. Further, the encrypted data is transmitted from an external transmission device, and the encrypted data acquisition means may acquire the encrypted data by receiving the encrypted data.
[0161] This makes it possible for each terminal to easily use the transmitted data such as digital contents by receiving the data. Further, the encryption key identification device according to the present invention is an encryption key identification device that specifies an encryption key to be used for encrypting distribution data to each of three or more terminals, and (a) each of the above. A plurality of terminal sets in which the same one or more terminals are included in each element so that the terminals belong to at least one of the terminal sets in which two or more terminals are included in the elements. Two or more terminal sets so that there is a relation that any one terminal set in the terminal set is not a subset of each other terminal set in the plurality of terminal sets. And (b) In addition to the decryption key group associating means for associating different decryption keys for each terminal and each determined terminal set, and the decryption key associated with the terminal by the decryption key setting means for each terminal. Decryption key setting means for associating all decryption keys associated with each of all terminal sets including the terminal with the terminal, invalidation terminal identification means for specifying one or more terminals as invalidation terminals, and the above. When the decryption key other than the decryption key associated with the invalidated terminal is defined as the valid decryption key among all the decryption keys associated with the terminal by the decryption key group mapping means, the selected valid decryption key is used. Assuming that the procedure of selecting the valid decryption key associated with the most unassociated terminals is repeated until there are no terminals that are not associated with the selected valid decryption key. It is characterized by including an encryption key specifying means for specifying an encryption key corresponding to each of all the valid decryption keys selected as a result.
[0162] Further, the encryption device according to the present invention is an encryption device that encrypts data for distribution to three or more terminals, and (a) each terminal has two or more terminals. A plurality of terminal sets including the same one or more terminals in each element so as to belong to at least one of the terminal sets which are sets included in the element, and any one terminal in the plurality of terminal sets. Two or more terminal sets are determined so that there is a relation that the set is not a subset of each other terminal set in the plurality of terminal sets, and (b) In addition to the decryption key setting means for associating a separate decryption key for each terminal and each determined terminal set, and the decryption key associated with the terminal by the decryption key setting means for each terminal, the terminal. Decryption key group mapping means for associating all the decryption keys associated with each of all the terminal sets including the above with the terminal, invalidation terminal identification means for specifying one or more terminals as invalidation terminals, and the above. When a decryption key other than the decryption key associated with the invalidated terminal among all the decryption keys associated with the terminal by the decryption key group mapping means is defined as the valid decryption key, the selected valid decryption key is used. Assuming that the procedure of selecting the valid decryption key associated with the most unassociated terminals is repeated until there are no terminals that are not associated with the selected valid decryption key. , As a result, the encryption key specifying means for specifying the encryption key corresponding to each of the selected valid decryption keys and all the encryption keys specified by the encryption key specifying means are sequentially used and distributed. It is characterized by including an encryption means for encrypting data for use and generating an encrypted distribution data group, and an output means for outputting the encrypted distribution data group generated by the encryption means to the outside.
[0163] Further, the encryption key identification method according to the present invention is an encryption key identification method for specifying an encryption key to be used for encrypting distribution data to each of three or more terminals. Each terminal is a plurality of terminal sets including the same one or more terminals in each element so that each terminal belongs to at least one of the terminal sets which is a set including two or more terminals in the element. Two or more terminal sets so that there is a relation that any one terminal set in the plurality of terminal sets is not a subset of each other terminal set in the plurality of terminal sets. A terminal set determination step for determining a terminal set, a decryption key associating step for associating a separate decryption key for each terminal and each terminal set determined by the terminal set determination step, and the decoding for each terminal. In addition to the decryption key associated with the terminal by the key mapping step, the decryption key group mapping step of associating all the decryption keys associated with each of all the terminal sets including the terminal with the terminal. The invalidation terminal identification step that identifies one or more terminals as the invalidation terminal, and the decryption key associated with the invalidation terminal among all the decryption keys associated with the terminal by the decryption key group mapping step. When a decryption key other than the above is defined as a valid decryption key, the procedure of selecting the valid decryption key associated with the most terminals to which the selected valid decryption key is not associated is selected and valid. It is characterized by including an encryption key identification step that specifies an encryption key corresponding to each of all the valid decryption keys that have been selected as a result of repeating until there is no terminal to which the decryption key is not associated. To do.
[0164] As a result, for example, in the case of recording the encrypted result data on the recording medium and distributing the recording medium to each terminal, the number of encryption keys used for encryption can be suppressed to a relatively small number. Therefore, after suppressing the increase in the amount of data recorded on the recording medium, when the decryption key held by the specific terminal is exposed by an unauthorized person by analysis of the specific terminal or the like, the specific terminal is exposed. Then, the data cannot be decrypted correctly, and the encryption can be performed so that the data can be decrypted correctly on other terminals.
BRIEF DESCRIPTION OF THE DRAWINGS [Fig. 1] Fig. 1 is a schematic configuration diagram of a data protection system 100 according to a first embodiment of the present invention.
FIG. 2 is a functional configuration diagram of an encryption device 101 and a decryption device 103a.
FIG. 3 is a functional configuration diagram of a key setting system 104.
FIG. 4 is a diagram showing a tree structure of a quadtree.
FIG. 5 is a diagram showing an example of a quadtree tree structure when the number of decoding devices is 64.
FIG. 6 is a diagram showing an example of route invalidation information.
FIG. 7 is a diagram showing an example of route invalidation information.
FIG. 8 is a diagram showing keys assigned to nodes in the level 0 and level 1 hierarchies of a quadtree tree structure.
FIG. 9 is a diagram showing a configuration of key information stored in the key information storage unit 301.
FIG. 10 is a flowchart showing a key allocation process executed by the decryption key determination unit 305.
FIG. 11 shows the decryption key group 905 assigned to the decryption device (terminal 1) corresponding to the leaf of the relative number 1 of level 3 and the decryption key group 905 determined by the key allocation process when it is assumed that there are only 64 decryption devices. It is a figure which shows.
FIG. 12 is a flowchart showing an invalidation information update process executed by the key information update unit 304.
FIG. 13 is a flowchart showing a key identification process executed by the encryption key identification unit 306.
FIG. 14 is a diagram showing an encryption key and the like in a state where there is no invalidation terminal when it is assumed that there are only 64 decryption devices.
FIG. 15 is a diagram showing an encryption key and the like in a state where the terminal 1 is an invalidated terminal when it is assumed that there are only 64 decryption devices.
FIG. 16 is a diagram showing an example of key identification information corresponding to the encryption key shown in FIG.
FIG. 17 is a diagram showing an example of a tree structure of four quadtrees constructed when the number of decoding devices is 64 in the second data protection system according to the second embodiment.
FIG. 18 is a diagram showing an encryption key and the like in a state where the terminal 1 is an invalidated terminal in the second data protection system.
FIG. 19 is a diagram showing a decryption key assigned to each node in the quadtree tree structure used in the third embodiment.
FIG. 20 is a diagram showing a decoding key group 1705 assigned to a decoding device (terminal 1) corresponding to a leaf of level 3 relative number 1 when it is assumed that there are only 64 decoding devices.
FIG. 21 is a diagram showing an encryption key and the like in a state where terminals 1, terminal 2 and terminal 17 are invalid terminals when it is assumed that there are only 64 decryption devices.
FIG. 22 is a schematic configuration diagram of a fourth data protection system according to a fourth embodiment of the present invention.
[Description of Code] 100 Data Protection System 101 Encryption Device 102 Optical Disk 103a ~ 103n Decryption Device 104 Key Setting System 201 Content Storage Unit 202 Random Generation Unit 203 Encryption Key Group Storage Unit 204 Key Encryption Unit 205 Content Encryption Unit 206 Output unit 211 Acquisition unit 212 Decryption key group storage unit 213 Decryption key selection unit 214 Key decryption unit 215 Content decryption unit 216 Playback unit 301 Key information storage unit 302 Key information generation unit 303 Invalidation terminal identification unit 304 Key information update unit 305 Decryption Key determination unit 306 Encryption key identification unit 1501 Key identification information recording device 1502a ~ 1502n User data encryption device
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office |
|---|---|---|
| JP2001500650A | Cites | Japan |
| JP2000099385A | Cites | Japan |
34 members in 10 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 2001095730 | Japan | A | |
| 2001095730 | Japan | – | |
| 2001285608 | Japan | A | |
| 2001285608 | Japan | – | |
| 2002089674 | Japan | A | |
| 2001200195730 | – | – | – |
| 20012001285608 | – | – | – |
| JP20010095730 | – | – | – |
| JP20010285608 | – | – | – |
| JP20020089674 | – | – | – |
Members34
| Document | Office | Kind | |
|---|---|---|---|
| CA2419972A1 | Canada | A1 | |
| WO02078419A2 | World Intellectual Property Organization (WIPO) | A2 | |
| KR20030007760A | Republic of Korea | A | |
| BR0204744A | Brazil | A | |
| WO02078419A3 | World Intellectual Property Organization (WIPO) | A3 | |
| JP2003169048A | Japan | A | |
| US2003182565A1 | United States of America | A1 | |
| WO02078419B1 | World Intellectual Property Organization (WIPO) | B1 | |
| MXPA02011835A | Mexico | A | |
| EP1374476A2 | European Patent Office (EPO) | A2 | |
| CN1471771A | China | A | |
| JP2005204346A | Japan | A | |
| CN1310462C | China | C | |
| CN101005605A | China | A | |
| AU2002241312B2 | Australia | B2 | |
| AU2002241312B9 | Australia | B9 | |
| KR20080047487A | Republic of Korea | A | |
| US7395425B2 | United States of America | B2 | |
| JP4170304B2 | Japan | B2 | |
| JP2008263645A | Japan | A | |
| JP4199472B2This record | Japan | B2 | |
| EP2104051A2 | European Patent Office (EPO) | A2 | |
| KR100923805B1 | Republic of Korea | B1 | |
| KR100929336B1 | Republic of Korea | B1 | |
| US2010034388A1 | United States of America | A1 | |
| CA2419972C | Canada | C | |
| JP4870727B2 | Japan | B2 | |
| US8416953B2 | United States of America | B2 | |
| US2013236018A1 | United States of America | A1 | |
| EP2104051A3 | European Patent Office (EPO) | A3 | |
| EP1374476B1 | European Patent Office (EPO) | B1 | |
| US9130741B2 | United States of America | B2 | |
| BRPI0204744B1 | Brazil | B1 | |
| EP2104051B1 | European Patent Office (EPO) | B1 |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4199472
- Publication, DOCDB
- 4199472
- Publication, EPODOC
- JP4199472B
- Application
- 89674
- Application, DOCDB
- 2002089674
- Application, EPODOC
- JP20020089674
Titles2
- English
- Data protection system that protects data by applying encryption
- Japanese
- 暗号化を施すことによりデータを保護するデータ保護システム
Classification
- IPC, 3
- H04L9 08
- H04N5 91
- G11B20 10