Digital rights management method and apparatus
Abstract
This record has no abstract on file.
Term
Projected expiry 30 April 2027.
- Priority
- Filed
- Granted
- Today
- Projected expiry
22 claims: 18 independent, 4 dependent
- 1第1証明書失効リストを受信して前記第1証明書失効リストの発給者識別情報を確認する確認段階と、 前記発給者識別情報に対応する第2証明書失効リストをロードし、前記第1証明書失効リストと前記第2証明書失効リストのうち何れかが最新の証明書失効リストであるのかを比較する比較段階、および 前記比較結果に基づいて、前記第1証明書失効リストおよび前記第2証明書失効リストのうち何れか一つを前記最新の証明書失効リストに更新する更新段階と、を含 み、 前記確認段階は、前記第1証明書失効リストに設定された値および前記第2証明書失効リストに設定された値のうち何れか一つが臨界値に到達した時に実行される、 デ ジタル著作権管理のための多重証明書失効リストのサポート方法。
- 2前記確認段階は、装置間の相互認証実行時に実行される、請求項1に記載のデジタル著作権管理のための多重証明書失効リストのサポート方法。
- 3前記第1証明書失効リストおよび前記第2証明書失効リストに設定された値は、前記識別情報を有する発給者別に設定可能である、請求項 1 に記載のデジタル著作権管理のための多重証明書失効リストのサポート方法。
- 4前記更新段階は、前記比較結果に基づいて、前記第2証明書失効リストを前記第1証明書失効リストに更新する、請求項1に記載のデジタル著作権管理のための多重証明書失効リストのサポート方法。
- 5前記更新段階は、前記比較結果に基づいて、前記第1証明書失効リストを前記第2証明書失効リストに更新する請求項1に記載のデジタル著作権管理のための多重証明書失効リストのサポート方法。
- 6前記更新段階は、前記比較結果に基づいて、前記第1証明書失効リストを前記第2証明書失効リストに更新するように要請する段階を含む、請求項1に記載のデジタル著作権管理のための多重証明書失効リストのサポート方法。
- 7第1 証明書失効リスト に含まれる 発給者識別情報 が発信先で確認される前記第1 証明書失効リストを発信する発信段階と、 前記発信先が、前記発給者識別情報に対応する第2証明書失効リストと、前記第1証明書失効リストとのうち何れかが最新の証明書失効リストであるのかを比較した結果に基づいて送信した、 前記証明書失効リストが更新されたことを知らせる応答メッセージ、および更新要請メッセージのうち何れか一つを受信する受信段階、および 前記応答メッセージおよび前記更新要請メッセージのうち何れか一つに基づいて、前記証明書失効リストを更新するかどうかを決定する更新段階と、を含 み、 前記発信段階は、前記第1証明書失効リストに設定された値が臨界値に到達した時に実行される、 デ ジタル著作権管理のための多重証明書失効リストのサポート方法。
- 8前記発信段階は、装置間の相互認証実行時に実行される、請求項 7 に記載のデジタル著作権管理のための多重証明書失効リストのサポート方法。
- 9前記証明書失効リストに設定された値は、前記識別情報を有する発給者別に設定可能である、請求項 7 に記載のデジタル著作権管理のための多重証明書失効リストのサポート方法。
- 10前記更新要請メッセージに対する応答を受信する場合、前記最新の証明書失効リストを受信する、請求項 7 に記載のデジタル著作権管理のための多重証明書失効リストのサポート方法。
- 11第1証明書失効リストを受信して前記第1証明書失効リストの発給者識別情報を確認する識別情報確認部と、 前記確認された発給者識別情報に対応する第2証明書失効リストをロードして、前記第1証明書失効リストと前記第2証明書失効リストのうち何れかが最新の証明書失効リストであるのかを比較する更新判断部、および 前記更新判断部による比較結果に基づいて、前記第1証明書失効リストおよび前記第2証明書失効リストのうち何れか一つを前記最新の証明書失効リストに更新する更新部と、を含 み、 識別情報確認部は、前記第1証明書失効リストに設定された値および前記第2証明書失効リストに設定された値のうち何れか一つが臨界値に到達した時、前記発給者識別情報を確認する、 デ ジタル著作権管理のための多重証明書失効リストのサポート装置。
- 12識別情報確認部は、装置間の相互認証実行時に、前記発給者識別情報を確認する、請求項 11 に記載のデジタル著作権管理のための多重証明書失効リストのサポート装置。
- 13前記第1証明書失効リストおよび前記第2証明書失効リストに設定された値は、前記識別情報を有する発給者別に設定可能である、請求項 11 に記載のデジタル著作権管理のための多重証明書失効リストのサポート装置。
- 14前記更新部は、前記比較結果に基づいて前記第2証明書失効リストを前記第1証明書失効リストに更新する請求項 11 に記載のデジタル著作権管理のための多重証明書失効リストのサポート装置。
- 15前記更新部は、前記比較結果に基づいて、前記第1証明書失効リストを前記第2証明書失効リストに更新する請求項 11 に記載のデジタル著作権管理のための多重証明書失効リストのサポート装置。
- 16前記更新部は、前記比較結果に基づいて前記第1証明書失効リストを前記第2証明書失効リストに更新するように要請する請求項 11 に記載のデジタル著作権管理のための多重証明書失効リストのサポート装置。
- 17第1 証明書失効リスト に含まれる 発給者識別情報 が発信先で確認される前記第1 証明書失効リストを発信する発信部と、 前記発信先が、前記発給者識別情報に対応する第2証明書失効リストと、前記第1証明書失効リストとのうち何れかが最新の証明書失効リストであるのかを比較した結果に基づいて送信した、 前記証明書失効リストが更新されたことを知らせる応答メッセージ、および更新要請メッセージのうち何れか一つを受信する受信部、および 前記応答メッセージおよび前記更新要請メッセージのうち何れか一つに基づいて、前記証明書失効リストを更新するかどうかを決定する更新判断部と、を含 み、 前記発信部は、前記第1証明書失効リストに設定された値が臨界値に到達した時、前記証明書失効リストを発信する、 デ ジタル著作権管理のための多重証明書失効リストのサポート装置。
- 18前記発信部は、装置間の相互認証実行時に、前記証明書失効リストを発信する請求項 17 に記載のデジタル著作権管理のための多重証明書失効リストのサポート装置。
- 19前記証明書失効リストに設定された値は、前記識別情報を有する発給者別に設定可能である、請求項 17 に記載のデジタル著作権管理のための多重証明書失効リストのサポート装置。
- 20前記受信部は、前記更新要請メッセージに対する応答を受信する場合、前記最新の証明書失効リストを受信する、請求項 17 に記載のデジタル著作権管理のための多重証明書失効リストのサポート装置。
- 21第1証明書失効リストを受信して、前記第1証明書失効リストの発給者識別情報を確認する 確認 段階と、 前記発給者識別情報に対応する第2証明書失効リストをロードし、前記第1証明書失効リストと前記第2証明書失効リストのうち何れかが最新の証明書失効リストであるのかを比較する 比較 段階、および 前記比較結果に基づいて、前記第1証明書失効リストおよび前記第2証明書失効リストのうち何れか一つを前記最新の証明書失効リストに更新する 更新 段階と、を含 み、 前記確認段階は、前記第1証明書失効リストに設定された値および前記第2証明書失効リストに設定された値のうち何れか一つが臨界値に到達した時に実行される、 デ ジタル著作権管理のための多重証明書失効リストのサポート方法を実行するためのコンピュータプログラムを保存する、コンピュータで判読可能な記録媒体。
- 22第1 証明書失効リスト に含まれる 発給者識別情報 が発信先で確認される前記第1 証明書失効リストを発信する 発信 段階と、 前記発信先が、前記発給者識別情報に対応する第2証明書失効リストと、前記第1証明書失効リストとのうち何れかが最新の証明書失効リストであるのかを比較した結果に基づいて送信した、 前記証明書失効リストが更新されたことを知らせる応答メッセージ、および更新要請メッセージのうち何れか一つを受信する 受信 段階、および 前記応答メッセージおよび前記更新要請メッセージのうち何れか一つに基づいて、前記証明書失効リストを更新するかどうかを決定する 更新 段階と、を含 み、 前記発信段階は、前記第1証明書失効リストに設定された値が臨界値に到達した時に実行される、 デ ジタル著作権管理のための多重証明書失効リストのサポート方法を実行するためのコンピュータプログラムを保存するコンピュータで判読可能な記録媒体。
Independent claims22
128 paragraphs, as filed
The present invention relates to multiple CRL support methods and devices for DRM, and more specifically, trust between various DRM devices by separately managing CRLs issued by different CRL issuers. It relates to the support method and device of multiple CRLs for DRM that guarantees.
Recently, research on digital DRM has been active, and commercial services applying DRM have been introduced or are being introduced.
Unlike analog data, digital data can be copied without loss, can be easily reused and processed, and can be easily distributed to third parties.
Also, copying and distribution of such digital data is possible at very low cost. Compared to this, it takes a lot of money, effort and time to produce digital contents, so technologies for protecting various digital copyrights are required, and for this reason, the scope of application of DRM is limited. It is being expanded gradually.
Efforts to protect digital content have been made in the past, but this has focused primarily on preventing unauthorized access to digital content.
Therefore, access to digital content was only allowed to some people who paid for it, and those who did not pay for it could not access digital content.
However, if a person who accesses the digital content for a fee intentionally distributes it to a third party, the third party can use the digital content without paying the price, which causes many problems.
In comparison, DRM allows unlimited access to digital content, but requires a specific license to encrypt and execute digital content. Therefore, applying DRM can protect digital content more effectively.
FIG. 1 is a diagram showing a general concept of DRM.
The main content of DRM is related to the handling of content protected by methods such as encryption or scrambling (hereinafter referred to as encrypted content) and the handling of licenses that enable access to encrypted content. ..
Figure 1 issues devices 110,150 that want access to encrypted content, Content Issuer 120 that supplies the content, and Rights Object (RO) that contains a license that allows the content to run. The Rights Issuer (RI) 130 and the certification authority 140 that issues the certificate are illustrated.
Device A (110) can obtain the desired content from the content supplier 120, which content is encrypted content.
Device A (110) can purchase a rights object containing a license to use the encrypted content from the rights object issuer 130, and device A (110) that purchased the rights object is encrypted. Content can be used.
Since the encrypted content can be freely distributed and distributed, the device A (110) can freely transmit the encrypted content to the device B (150).
Device B (150) also needs a rights object to play the transmitted encrypted content, and such a rights object can be obtained from the rights object issuer 130.
The certification authority 140 is a proof that a message indicating the name of the device whose public key has been confirmed, the serial number of the certificate, the name of the certification authority issuing the certificate, the public key of the corresponding device, and the expiration date of the certificate is signed. Issue a certificate.
Each device can confirm whether the device communicating with each device is a legitimate device by the certificate issued by the certification authority 140.
Since each certificate is signed with the private key of the certification authority 140 to confirm its approval, the device uses the public key of the certification authority 140 to obtain the certificates of other devices that communicate with each device. You can check.
Certificates can also be stored in a location that is easily accessible by each device, such as a directory service system, or on each device itself.
All devices must be issued a device certificate by the certification authority 140 for increased communication security.
However, the certificate issued by the certification body 140 may be revoked before its expiration date.
For example, if the private key of a particular device is damaged or leaked to the outside world, the revocation of the certificate of that device can allow other devices to verify this.
Various methods have been proposed to check whether a certificate that has not expired has expired, one of which is to obtain the certificate of all valid devices that are located online. Store it in an easily accessible directory service system and make it publicly available.
For example, when a device attempts to connect to a server, the server can connect to a directory service system and check for the device's certificate.
If the device certificate does not exist in the directory service system, the server can determine that the device certificate has been revoked.
Another way to check if a certificate has been revoked is for the certification authority to issue a Certificate Revocation List (CRL), which is a list of revoked certificates.
Such CRLs are updated regularly / irregularly and newly issued, and the issued certificate revocation list can be distributed by the certification authority.
Each device searches the recently issued certificate revocation list for the certificates of other devices that communicate with the device, and determines that the device is valid if the certificate is not on the certificate revocation list. can do.
If the certificate of the other party's device is included in the certificate revocation list, it is possible to determine that the other party's device is an illegal device and interrupt the communication with the other party's device.
FIG. 2 is a diagram showing CRL issuance and renewal in a conventional DRM system.
CRL issuer 201 creates a CRL (201a) for certificate revocation records for all devices 202 to 204 that make up a Digital Rights Management (DRM) system, distributes it through network 205, and distributes it through network 205. System components 202-204 receive and store the latest CRLs from the CRL issuer 201 or other devices 202-204.
When communicating with other devices, each device 202 to 204 inspects the CRL (201a) to determine whether the other device is damaged, and at this time, the CRL (201a) stored in the two devices is checked. If the issuance times are not the same in comparison, the old CRL is updated with the latest CRL.
However, in the case of the prior art, conflicts can occur when CRLs issued by two or more other CRL issuers are stored in one device.
In other words, at the time of CRL inspection and update, it is difficult to design a distributed CRL considering the type of DRM, DRM system device, CRL issuer, etc., because the relevant device does not know which CRL must be loaded. There is.
Furthermore, since the CRL for all the devices that make up the DRM system is recorded in one CRL, the size of the CRL becomes large, and when communicating between two devices, when inspecting the CRL of the other device, it is necessary for other devices. There is also a problem that the efficiency of CRL management becomes low, such as having to exchange information that is not the same.
<p> The present invention guarantees trust between various DRM devices by separately managing CRLs issued by different CRL issuers by supporting multiple certificate revocation lists for digital rights management and devices. Its purpose is to do.</p><p> The object of the present invention is not limited to the object mentioned above, and other purposes not mentioned above will be clearly understood by those skilled in the art from the following description.</p>
<p> In order to achieve the above object, the method of supporting the multiple certificate revocation list for digital copyright management according to the embodiment of the present invention is to receive the first certificate revocation list and issue the first certificate revocation list. The confirmation stage for confirming the identification information and the second certificate revocation list corresponding to the issuer identification information are loaded, and either the first certificate revocation list or the second certificate revocation list is the latest proof. Based on the comparison stage for comparing whether it is a certificate revocation list and the comparison result, any one of the first certificate revocation list and the second certificate revocation list is added to the latest certificate revocation list. Including the update stage to update and<u style="single">Only, the confirmation step is executed when any one of the value set in the first certificate revocation list and the value set in the second certificate revocation list reaches the critical value.</u>。 </p><p> A method of supporting a multiple certificate revocation list for digital rights management according to another embodiment of the present invention in order to achieve the above object is described.<u style="single">1st</u>Certificate revocation list<u style="single">include</u>Issuer identification information<u style="single">Is confirmed at the destination</u>The sending stage to send the certificate revocation list and<u style="single">Based on the result of comparing whether the second certificate revocation list corresponding to the issuer identification information and the first certificate revocation list are the latest certificate revocation lists. sent,</u>Based on the receiving stage for receiving any one of the response message notifying that the certificate revocation list has been updated and the renewal request message, and any one of the response message and the renewal request message. Includes an renewal stage, which determines whether to renew the certificate revocation list.<u style="single">Only, the transmission stage is executed when the value set in the first certificate revocation list reaches the critical value.</u>。 </p><p> In order to achieve the above object, the support device for the multiple certificate revocation list for digital copyright management according to the embodiment of the present invention receives the first certificate revocation list and identifies the issuer of the first certificate revocation list. Load the identification information confirmation unit that confirms the information and the second certificate revocation list corresponding to the confirmed issuer identification information, and either the first certificate revocation list or the second certificate revocation list. One of the first certificate revocation list and the second certificate revocation list based on the comparison result by the renewal judgment unit that compares whether or not is the latest certificate revocation list, and the comparison result by the renewal judgment unit. Includes an update section that updates one to the latest certificate revocation list<u style="single">Only, when any one of the value set in the first certificate revocation list and the value set in the second certificate revocation list reaches the critical value, the identification information confirmation unit identifies the issuer. Check the information</u>。 </p><p> To achieve the above object, a support device for a multiple certificate revocation list for digital rights management according to another embodiment of the present invention is provided.<u style="single">1st</u>Certificate revocation list<u style="single">include</u>Issuer identification information<u style="single">Is confirmed at the destination</u>The originator that sends the certificate revocation list and<u style="single">Based on the result of comparing whether the second certificate revocation list corresponding to the issuer identification information and the first certificate revocation list are the latest certificate revocation lists. sent,</u>Based on the receiver that receives any one of the response message notifying that the certificate revocation list has been updated and the renewal request message, and any one of the response message and the renewal request message. Includes a renewal decision unit that determines whether to renew the certificate revocation list.<u style="single">Then, when the value set in the first certificate revocation list reaches the critical value, the transmitting unit transmits the certificate revocation list.</u>。 </p><p> Specific contents of other embodiments are included in detailed explanations and figures.</p>
<p> According to the method and device for supporting the multiple certificate revocation list for digital rights management of the present invention as described above, the following effects are one or more.</p><p> CRL management is possible for each institution and device by the CRL issuer individually and according to the purpose, so there is no need to maintain and manage unnecessary CRLs, and the size of CRLs managed within one device can be reduced. It has the advantage of reducing it and increasing management efficiency.</p><p> In addition, since the required CRL can be directly managed by the CRL issuer, when the CRL issued by various organizations is stored and used in one device, it has the advantage of preventing collisions caused by different CRL issuers. There is also.</p><p> Furthermore, in the case of a device that supports multi-DRM, when a specific DRM is operating, the CRL issuer can manage the required CRL for each DRM type, so there is an advantage that only the CRL related to the corresponding type of DRM is managed separately. ..</p>
The advantages, features, and methods of achieving them of the present invention will become apparent with reference to embodiments described in detail with the accompanying drawings.
However, the present invention is not limited to the embodiments disclosed below, and can be embodied in various forms different from each other. The present embodiment is provided solely for the purpose of fully informing a person having ordinary knowledge in the technical field to which the present invention belongs, so that the disclosure of the present invention is complete. The invention is defined only by the scope of the claims.
It should be noted that the same reference numerals refer to the same components throughout the specification.
Hereinafter, the present invention will be described with reference to a configuration diagram or a diagram for a processing flowchart for explaining a support method and an apparatus for a multiple certificate revocation list for digital rights management according to an embodiment of the present invention.
At this time, it can be understood that the combination of each block of the flowchart and the flow chart can be executed by the computer program instruction.
Since these computer program instructions can be installed in a general purpose computer, a special computer, or a processor equipped with other programmable data processing, the instructions executed through the computer or a processor equipped with other programmable data processing are described in blocks of the flowchart. Mechanisms can be created to generate means of performing these functions.
These computer program instructions can also be stored in computer-enabled or computer-readable memory that can point the computer or other programmable data processing equipment to implement its functionality in a particular manner, so that it is computer-enabled or computer-readable. Instructions stored in memory can also produce manufactured items that include instructional means that perform the functions described in the blocks of the flowchart.
Computer program instructions can also be mounted on a computer or other programmable data processing equipment, so that a series of operating steps are performed on the computer or other programmable data processing equipment to spawn processes that run on the computer. Alternatively, instructions with other programmable data processing equipment can also provide steps to perform the functions described in the blocks of the flowchart.
Also, each block can represent a part of a module, segment or code that contains one or more executable instructions to perform a particular logical function.
It should also be noted that in some alternative execution examples, the functions mentioned in the block can occur out of order.
For example, two blocks shown in succession may be performed substantially simultaneously, or the blocks may sometimes be performed in reverse order by the corresponding function.
Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings.
FIG. 3 is a diagram showing a method of managing multiple CRLs according to an embodiment of the present invention, in which various devices 304 to 306 and a plurality of CRL issuers 301 to 303 that constitute a DRM system exist, and each CRL issuer. For 301 to 303, CRL 301a to 303a for each device are created and distributed through network 307 in order to manage CRL efficiently.
At this time, since each CRL 301a to 303a contains information that can distinguish the CRL issuers 301 to 303 that issued the corresponding CRL 301a to 303a (for example, the issuer ID), the devices 304 to 306 constituting the DRM system are different from each other. CRL 301a to 303a issued by CRL issuers 301 to 303 can be saved, replaced and updated.
Hereinafter, the multiple CRL support method and device illustrated in FIG. 3 will be described in detail with reference to FIGS. 4 to 6.
At this time, the devices that make up the DRM system include the client and server, and the two devices (client and server) store the CRLs issued by two or more CRL issuers, and the corresponding CRLs are issued to the CRLs. It is assumed that the identification information that can distinguish the CRL issuer, that is, the CRL issuer ID is included.
It is also assumed that communication between two devices is possible through a predetermined protocol, and that one of the two devices meets the CRL inspection conditions and the CRL update is performed.
Here, the CRL inspection condition means when mutual authentication is performed, which requires verification between devices, and when the CRL reaches a specific critical value, and there is one or more specific critical values for each CRL issuer ID. Can be set, and if the set specific critical value is reached, some of the functions of the device will be restricted.
For example, a multimedia security card CRL issuer can set a specific critical value for the number of exchanges of data stored on the security card, and a device CRL issuer can set a specific period to a critical value and the corresponding number of times. And when the relevant period is reached, access to copyright objects is restricted.
Of course, after updating to a new CRL, certain critical values are initialized and the functions restricted by reaching the critical values are lifted.
FIG. 4 is a flowchart showing a CRL support method according to an embodiment of the present invention.
First, the client transmits the CRL of the server owned by the client to the server together with the update request message (S401).
At this time, the transmission time of S401 is when the above-mentioned CRL inspection condition is satisfied.
After S401, the server receives the update request message transmitted to the client and the server's CRL and confirms the CRL issuer ID included in the received CRL (S402).
After S402, the server corresponds to the CRL issuer ID confirmed in S402, that is, loads the server's CRL issued by the issuer and compares whether the loaded CRL is more up-to-date than the CRL received from the client. (S403).
As a result of the comparison, if the CRL received from the client is the latest, the server updates the CRL of the server to the CRL received from the client (S404) and sends a response message to the client informing that the update is completed (S405). ..
For reference, the update in S404 is to use the latest CRL of the client received by discarding the CRL of the server on the server as a new CRL of the server, or the latest CRL of the client received without discarding the CRL of the server on the server. It is possible to refer to the CRL of the server and make the CRL of the server look like the CRL of the client.
If, as a result of S403, the server CRL is more up-to-date than the CRL received from the client, the server saves the server CRL (S406) and sends a response message informing the client that the CRL received from the client needs to be updated. (S407).
At this time, the server can transmit the latest CRL of the server together with the response message.
After S407, the client receives a response message and the latest CRL from the server and updates the client's CRL to the latest CRL received (S408).
For reference, the update in S408 does not discard the client CRL on the client and uses the latest CRL of the received server as the new CRL of the client, or does not discard the client CRL on the client and the latest of the received server. It is possible to refer to the CRL of the client so that the CRL of the client is the same as the CRL of the server.
FIG. 5 is a flowchart showing a CRL support method according to another embodiment of the present invention.
The client's own CRL, including the CRL issuer ID that the client wants to confirm, is transmitted to the server along with the solicitation message (S501).
At this time, the transmission time of S501 is when the above-mentioned CRL inspection condition is satisfied.
After S501, the server receives the client's CRL and solicitation message and verifies the CRL issuer ID contained in the received client's CRL (S502).
After S502, the server corresponds to the CRL issuer ID confirmed in S502, that is, loads the CRL of the server issued by the issuer (S503) and transmits the loaded CRL to the client (S504).
After S504, the client receives the server CRL from the server and compares which of the server CRL and the client CRL is up-to-date (S505).
As a result of the comparison, if the received server CRL is the latest, the client updates its CRL to the server CRL (S506) and sends a response message to the server notifying that the update is complete (S507).
For reference, the update in S506 does not discard the client CRL on the client and uses the latest CRL of the received server as the new CRL of the client, or does not discard the client CRL on the client and the latest of the received server. It is possible to refer to the CRL of the client so that the CRL of the client is the same as the CRL of the server.
If, as a result of S505, the client's own CRL is more up-to-date than the received server's CRL, the client sends a response message to the server informing it that it needs to save its own CRL (S508) and update the server's CRL. Transmit (S509).
At this time, the client can transmit its latest CRL together with the response message.
After S509, the server receives the response message and the latest CRL from the client, updates the server's CRL to the latest received CRL (S510), and sends a response message to the client notifying that the update is complete. (S511).
For reference, the update on S510 does not discard the server CRL on the server and uses the latest CRL of the received client as a new CRL of the server, or does not discard the CRL of the server on the server and receives the latest client. It is possible to refer to the CRL of the server so that the CRL of the server is the same as the CRL of the client.
FIG. 6 is a flowchart showing a CRL support method according to another embodiment of the present invention.
It is transmitted to the server with a message requesting an update of the client's own CRL, including the CRL issuer ID that the client wants to confirm (S601).
At this time, the transmission time of S601 is when the above-mentioned CRL inspection condition is satisfied.
After S601, the server receives the client's CRL and update request message and verifies the CRL issuer ID contained in the received client's CRL (S602).
After S602, the server corresponds to the CRL issuer ID confirmed in S602, that is, loads the server CRL issued by the issuer and compares whether the loaded CRL is more up-to-date than the received client CRL. (S603).
As a result of the comparison, if the received client CRL is the latest, the server updates the server CRL to the received CRL from the client (S604) and sends a response message to the client notifying that the update is complete (S605). ..
For reference, the update in S604 discards the server CRL on the server and uses the latest CRL of the received client as a new CRL of the server, or does not discard the server CRL on the server and receives the latest client. It is possible to refer to the CRL of the server so that the CRL of the server is the same as the CRL of the client.
If, as a result of S603, the server CRL is more up-to-date than the received client CRL, the server saves its own CRL (S606), updates the received client CRL (S607), and updates the client CRL. Send the updated client CRL to the client with a response message informing it that it has been done (S608).
For reference, after S606, the server discards the client's CRL and sends the server's latest CRL to the client along with the response message so that the client can use the server's latest CRL, or the client that received it. You can also update the CRL in the server to be the same as the latest CRL on the server, and send the updated client CRL to the client with a response message informing you that the client CRL has been updated, as shown in Figure 6. Then, for convenience of explanation, the latter case has been described as an example.
FIG. 7 is a block diagram showing a configuration of a multiplex CRL support device for DRM according to an embodiment of the present invention.
The multiplex CRL support device 700 for DRM according to the embodiment of the present invention receives the first certificate revocation list and confirms the issuer identification information of the first certificate revocation list. Whether the 2nd certificate revocation list or the 1st certificate revocation list loaded by loading the 2nd certificate revocation list corresponding to the issuer identification information confirmed by the information confirmation unit 701 is the latest Update unit 703 that updates any one of the first certificate revocation list and the second certificate revocation list to the latest certificate revocation list according to the comparison result of the renewal judgment unit 702 and the renewal judgment unit 702 to be compared. Including.
FIG. 8 is a block diagram showing the configuration of a multiplex CRL support device for DRM according to another embodiment of the present invention.
The multiple CRL support device 800 for DRM according to another embodiment of the present invention is a first certificate revocation list including the issuer identification information of the certificate revocation list. Depending on whether the certificate revocation list is up-to-date, depending on the response received by the receiver 802 and the receiver 802 that receive a response to any one of the update completion and update request of the first certificate revocation list. Includes Renewal Unit 803, which determines whether to renew the first certificate revocation list.
The components illustrated in FIGS. 7 to 8 according to an embodiment of the present invention mean hardware components such as software, FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit), and are predetermined. Fulfill function.
However, the components are not meant to be limited to software or hardware, and each component may be configured to be on a storage medium that can be addressed, and is configured to play one or more processors. You can also do it.
Thus, the components in the embodiment are components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, processors, subroutines, and program code. Includes segments, drivers, firmware, microcodes, circuits, data, databases, data structures, tables, arrays, and variables.
The functionality provided by a component and the component in question can be combined into a smaller number of components or further separated into additional components.
For reference, the devices that make up the DRM system include the client and server, and the two devices (client and server) store CRLs issued by two or more CRL issuers, respectively, and correspond to CRLs. It is assumed that the identification information that can distinguish the CRL issuer who issued the CRL, that is, the CRL issuer ID is included.
At this time, the device 700 shown in FIG. 7 is included in the server, the device 800 shown in FIG. 8 is included in the client, whereas the device 800 shown in FIG. 8 is included in the server. The client includes the device 700 illustrated in FIG. In addition, all servers and clients may include an update decision unit 702 to increase the reliability of the CRL update decision.
For convenience of explanation, in the embodiment of the present invention, the case where the device 700 shown in FIG. 7 is included in the server and the device 800 shown in FIG. 8 is included in the client will be described.
First, the device 800 shown in FIG. 8, that is, the transmission unit 801 of the client transmits the CRL including the CRL issuer ID to the device 700 shown in FIG. 7, that is, the server.
For reference, when the DRM system transmits a CRL including a CRL issuer ID and inspects the CRL according to the embodiment of the present invention, the CRL is specified at the time of performing mutual authentication that requires verification between devices. It is when the critical value is reached.
Here, one or more specific critical values can be set for each CRL issuer ID, and when the set specific critical value is reached, some of the functions of the device may be restricted.
For example, the multimedia security card CRL issuer can set a specific critical value for the number of exchanges of data stored in the security card, and the device CRL issuer can set a specific period as the critical value and set the corresponding number of times. When the relevant period is reached, access to the copyright object is restricted.
Of course, after updating to a new CRL, certain critical values are initialized and the restricted functionality is lifted by reaching the critical value.
The server identification information confirmation unit 701 receives the CRL (hereinafter referred to as the first CRL) transmitted by the client transmission unit 801 and confirms the CRL issuer ID which is the issuer identification information of the received first CRL. To do.
Here, the CRL issuer ID is identification information for classifying the CRL issuer in the CRL, and the configuration of the CRL issuer according to the embodiment of the present invention is a device that supports the reproduction of copyright-protected content. A host, CRL issuer, rights issuer by device type, including a multimedia card (Secure Removable Media) that securely stores and manages relevant information so that copyrighted content can be played. ) And CRL issuers with DRM system configurations such as Certificate Authority, CRL issuers by organizations operating DRM systems such as content service providers and DRM equipment manufacturers, OMA (Open Mobile Alliance) DRM and It can be classified as a CRL issuer by DRM type such as MSW (Micosoft Window Media) DRM.
For reference, in addition to the above-mentioned classification of CRL issuers, various CRL issuers can be classified as needed, and this is not limited to the embodiment of the present invention.
Therefore, based on the CRL issuer ID described above, the identification information confirmation unit 701 of the server confirms the CRL issuer ID of the received first CRL and determines which CRL the other device desires to verify.
The server update determination unit 702 has a CRL corresponding to the corresponding ID through the first CRL issuer ID confirmed by the identification information confirmation unit 701, that is, a CRL having the same CRL issuer ID (hereinafter referred to as the second CRL). From the server's repository.
For reference, the server repository can store encrypted content, rights objects, server certificates and CRLs.
The update determination unit 702 of the server loads the second CRL, compares which of the loaded second CRL and the received first CRL is the latest, and transmits the comparison result to the update unit 703.
Here, the comparison of whether or not it is the latest is based on the CRL issuance date, and the update judgment unit 702 determines that the latest CRL issuance date is the latest CRL.
The server update unit 703 determines which of the first CRL and the second CRL to update is determined based on the comparison result of the first CRL and the second CRL transmitted from the update determination unit 702, and the update target. Update the CRL that becomes the latest CRL.
For example, if the client's first CRL is the latest CRL than the server's second CRL, server update 703 updates the second CRL to the first CRL, but such updates are the server's repository. Informs that the server's second CRL has been updated to the client's first CRL after discarding the existing second CRL stored in and saving the client's first CRL as a new CRL in the server's repository. It can be an update that sends a response message to the client.
On the other hand, if the server's second CRL is more up-to-date than the client's first CRL, the server's update 703 updates the first CRL to the second CRL, but such updates are made by the server's update 703. Discard the 1st CRL and send the server CRL with a response message to inform it so that the client can update to the latest CRL of the server, or the server update section 703 does not discard the 1st CRL of the server. , After updating the first CRL of the client to the second CRL of the server, it can be an update that transmits the updated CRL of the client to the client with a response message notifying this, and the first CRL of the client in the update unit 703 of the server. The server's second CRL is transmitted to the client with a response message informing that the CRL needs to be updated without updating, and the client receives the latest CRL of the server and the latest of the server that received the CRL of the client. It could be to update to the CRL of.
If the issue date of the client's first CRL and the server's second CRL are the same, the communication between the server and the client is continuously maintained without updating the CRL.
On the other hand, the client receiving unit 802 responds to any one of the update completion and the update request of the first CRL from the server update unit 703 depending on whether the first CRL transmitted by the client transmission unit 801 is the latest. Receive a response message.
For example, if the first CRL sent by the client is newer than the second CRL of the server, the server update unit 703 updates the second CRL of the server to the first CRL of the client to notify that the update is complete. If the response message is transmitted, the receiving unit 802 of the client receives the corresponding response message.
After that, the update unit 803 of the client refers to the response message received by the receiver 802 and maintains communication with the server after completing the CRL update.
If the server's second CRL is more up-to-date than the client's first CRL, the server's update section 703 sends the server's second CRL with a response message informing it that the client's first CRL must be updated. If transmitted, the client receiver 802 receives the server's second CRL along with the corresponding response message.
After that, the update unit 803 of the client refers to the response message received by the receiver 802, discards the existing first CRL stored in the client's storage, and uses the second CRL of the server received through the receiver 802. Maintain communication with the server after saving as a new CRL in the client's repository.
If the server's second CRL is more recent than the client's first CRL, in addition to the method described above, the server update section 703 updates the client's first CRL to the server's second CRL. By transmitting the updated client CRL together with the response message informing the client, the client receiver 802 can end the CRL update and maintain communication with the server after receiving the corresponding response message and the updated CRL. ..
Although the embodiments of the present invention have been described above with reference to the accompanying drawings, a person having ordinary knowledge in the technical field to which the present invention belongs does not change the technical idea or essential features of the present invention. It is understandable that the scope can be implemented in other specific forms. Therefore, it should be understood that the embodiments described above are exemplary in all respects and are not limiting.
<figref num="1">It is a figure which shows the general concept of DRM.</figref><figref num="2">It is a figure which shows the CRL issuance and renewal in the conventional DRM system.</figref><figref num="3">It is a figure which shows the management of multiple CRL by embodiment of this invention.</figref><figref num="4">It is a flowchart which shows the CRL support method by embodiment of this invention.</figref><figref num="5">It is a flowchart which shows the CRL support method by another embodiment of this invention.</figref><figref num="6">It is a flowchart which shows the CRL support method by another Embodiment of this invention.</figref><figref num="7">It is a block diagram which shows the structure of the multiple CRL support apparatus for DRM by embodiment of this invention.</figref><figref num="8">It is a block diagram which shows the structure of the multiplex CRL support apparatus for DRM by another embodiment of this invention.</figref>
Code description
701 Identification information confirmation unit 702 Update Judgment Department 703 Update Department 801 Caller 802 receiver 803 Update Department
Every citation, both waysCites: the store holds 4 of 5
| Document | Relation | Office |
|---|---|---|
| JP2005045641A | Cites | Japan |
| WO2004044717A1 | Cites | World Intellectual Property Organization (WIPO) |
| WO2005124582A1 | Cites | World Intellectual Property Organization (WIPO) |
| JP2003115840A | Cites | Japan |
| 小松文子他,PKIハンドブック,ソフト・リサーチ・センター,2000年11月25日,p.69-71 | Non-patent | – |
84 members in 6 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 60799652 | United States of America | – | |
| 79965206 | United States of America | P | |
| 79965206 | United States of America | P | |
| 1020070010277 | Republic of Korea | – | |
| 20070010277 | Republic of Korea | A | |
| 20070010277 | Republic of Korea | A | |
| 2007002111 | Republic of Korea | W | |
| 2007002111 | Republic of Korea | W | |
| 2006799652 | – | – | – |
| 2007200710277 | – | – | – |
| 2007002111 | – | – | – |
| KR20070010277 | – | – | – |
| US20060799652P | – | – | – |
| WO2007KR02111 | – | – | – |
Members84
| Document | Office | Kind | |
|---|---|---|---|
| KR20070109797A | Republic of Korea | A | |
| KR20070109804A | Republic of Korea | A | |
| KR20070109813A | Republic of Korea | A | |
| KR20070109814A | Republic of Korea | A | |
| KR20070109823A | Republic of Korea | A | |
| KR20070109826A | Republic of Korea | A | |
| KR20070109834A | Republic of Korea | A | |
| KR20070109835A | Republic of Korea | A | |
| KR20070109851A | Republic of Korea | A | |
| US2007263869A1 | United States of America | A1 | |
| US2007265981A1 | United States of America | A1 | |
| US2007266208A1 | United States of America | A1 | |
| US2007266243A1 | United States of America | A1 | |
| US2007266260A1 | United States of America | A1 | |
| US2007266440A1 | United States of America | A1 | |
| US2007266441A1 | United States of America | A1 | |
| WO2007132987A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2007132988A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2007133007A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2007133009A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2007133024A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2007133026A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2007133028A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2007133029A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2007133035A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2007288383A1 | United States of America | A1 | |
| US2008052510A1 | United States of America | A1 | |
| EP2021945A1 | European Patent Office (EPO) | A1 | |
| EP2021946A1 | European Patent Office (EPO) | A1 | |
| EP2021947A1 | European Patent Office (EPO) | A1 | |
| EP2024846A1 | European Patent Office (EPO) | A1 | |
| EP2024864A1 | European Patent Office (EPO) | A1 | |
| EP2024894A1 | European Patent Office (EPO) | A1 | |
| EP2027540A1 | European Patent Office (EPO) | A1 | |
| EP2027545A1 | European Patent Office (EPO) | A1 | |
| KR100886338B1 | Republic of Korea | B1 | |
| EP2035968A1 | European Patent Office (EPO) | A1 | |
| CN101443744A | China | A | |
| CN101443745A | China | A | |
| CN101443754A | China | A | |
| CN101443755A | China | A | |
| CN101443756A | China | A | |
| CN101443757A | China | A | |
| CN101443758A | China | A | |
| CN101443764A | China | A | |
| CN101443772A | China | A | |
| JP2009537029A | Japan | A | |
| JP2009537039A | Japan | A | |
| JP2009537040A | Japan | A | |
| JP2009537041A | Japan | A | |
| JP2009537042A | Japan | A | |
| JP2009537043A | Japan | A | |
| JP2009537090A | Japan | A | |
| JP2009537092A | Japan | A | |
| JP2009537093A | Japan | A | |
| US7854010B2 | United States of America | B2 | |
| CN101443756B | China | B | |
| JP4810608B2 | Japan | B2 | |
| CN101443754B | China | B | |
| JP4859978B2 | Japan | B2 | |
| JP4865854B2 | Japan | B2 | |
| JP4896218B2 | Japan | B2 | |
| JP4907718B2This record | Japan | B2 | |
| KR101135145B1 | Republic of Korea | B1 | |
| US8196208B2 | United States of America | B2 | |
| CN101443758B | China | B | |
| CN101443772B | China | B | |
| US8261073B2 | United States of America | B2 | |
| US8340297B2 | United States of America | B2 | |
| KR101346734B1 | Republic of Korea | B1 | |
| KR101352524B1 | Republic of Korea | B1 | |
| KR101352513B1 | Republic of Korea | B1 | |
| KR101352515B1 | Republic of Korea | B1 | |
| KR101362380B1 | Republic of Korea | B1 | |
| CN103632072A | China | A | |
| US8677498B2 | United States of America | B2 | |
| EP2021946A4 | European Patent Office (EPO) | A4 | |
| EP2021947A4 | European Patent Office (EPO) | A4 | |
| US2016197891A1 | United States of America | A1 | |
| EP2027545A4 | European Patent Office (EPO) | A4 | |
| EP2024846A4 | European Patent Office (EPO) | A4 | |
| EP2024894A4 | European Patent Office (EPO) | A4 | |
| US9853953B2 | United States of America | B2 | |
| EP2024846B1 | European Patent Office (EPO) | B1 |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 4907718
- Publication, DOCDB
- 4907718
- Publication, EPODOC
- JP4907718B
- Application
- 2009509410
- Application, DOCDB
- 2009509410
- Application, EPODOC
- JP20090509410
Titles2
- Japanese
- デジタル著作権管理のための多重証明書失効リストのサポート方法および装置
- English
- Multiple Certificate Revocation List Support Methods and Devices for Digital Rights Management
Classification
- CPC, 17
- G06F21/10
- G06F21/107
- G06F17/00
- H04L63/0428
- G06F21/33
- H04L9/3268
- H04L63/0823
- H04L63/0869
- H04L2209/603
- G06Q20/027
- H04L9/3273
- H04L63/0442
- H04L63/0853
- G06F21/445
- G06F21/109
- H04L9/0816
- H04L2209/24
- IPC, 2
- G06F21 24
- H04L9 32