Content security layer providing long-term renewable security
Abstract
In an exemplary embodiment, digital content is mastered as a combination of encrypted data and data processing operations that enable use in approved playback environments. Player devices having a processing environment compatible with the content's data processing operations are able to decrypt and play the content. Players can also provide content with basic functions, such as loading data from media, performing network communications, determining playback environment configuration, controlling decryption/playback, and/or performing cryptographic operations using the player's keys. These functions allow the content to implement and enforce its own security policies. If pirates compromise individual players or content titles, new content can be mastered with new security features that block the old attacks. A selective decryption capability can also be provided, enabling on-the-fly watermark insertion so that attacks can be traced back to a particular player. Features to enable migration from legacy formats are also provided.
Term
Projected expiry 27 January 2032.
- Priority
- Filed
- Granted
- Today
- Projected expiry
40 claims: 25 independent, 15 dependent
- 1A method of controlling the playback of encrypted digital content by a playback device, in which a computer language interpreter of the playback device is used to execute a data processing command corresponding to the encrypted digital content.A query is made to the playback device, an encryption calculation is executed using the encryption key, and the result of the encryption calculation is acquired. Using the computer language interpreterIncluding the result of the cryptographic calculation,The security data of the playback device is received, the security data is analyzed using the computer language interpreter, and the security data is analyzed.By comparing the result of the cryptographic calculation with the predetermined value,The risk of the digital content being tampered with during playback by the playback device is evaluated, and based on the risk evaluation, the playback device is prevented from playing the digital content, or the playback device is the digital content. The method comprising decoding the digital content and enabling the digital content to be output in either the highest quality of the digital content or a degraded quality lower than the highest quality of the digital content. 再生デバイスによる暗号化されたデジタルコンテンツの再生を制御する方法であって、 前記再生デバイスのコンピュータ言語インタプリタを用いて、前記暗号化されたデジタルコンテンツに対応するデータ処理コマンドを実行し、前記再生デバイスに対してクエリを行い、暗号キーを用いて暗号計算を実行し、前記暗号計算の結果を取得し、 前記コンピュータ言語インタプリタを用いて、前記暗号計算の結果を含む、前記再生デバイスのセキュリティデータを受け取り、 前記コンピュータ言語インタプリタを用いて、前記セキュリティデータを分析し、前記暗号計算の結果と所定値とを比較することで、前記再生デバイスによる再生中に前記デジタルコンテンツが改ざんされるリスクを評価し、 前記リスク評価に基づいて、 前記再生デバイスが前記デジタルコンテンツを再生できないようにするか、または、 前記再生デバイスが前記デジタルコンテンツを復号し、かつ、前記デジタルコンテンツの最高品質か、前記デジタルコンテンツの該最高品質よりも低い劣化した品質のどちらかで前記デジタルコンテンツを出力できるようにすることを含む、方法。
- 4A claim that further comprises accessing the output interface of the playback device to detect at least one security characteristic of the output interface, and the risk assessment is performed based on the at least one security characteristic of the output interface. The method according to any one of Items 1 to 3. 前記再生デバイスの出力インタフェースにアクセスして、前記出力インタフェースのセキュリティ特性を少なくとも1つ検出することをさらに含み、 前記出力インタフェースの前記少なくとも1つのセキュリティ特性に基づいて、前記リスク評価が行われる、請求項1乃至3のいずれか1項に記載の方法。
- 6An optical medium, including encrypted digital content and a data processing command corresponding to the encrypted digital content, said data processing command when executed by the computer language interpreter of the playback device. The computer language interpreterA query is made to the playback device, an encryption calculation is executed using the encryption key, and the result of the encryption calculation is acquired. Including the result of the cryptographic calculation,Receive the security data of the playback device, analyze the security data,By comparing the result of the cryptographic calculation with the predetermined value,The risk of the digital content being tampered with during playback by the playback device is evaluated, and based on the risk evaluation, the playback device is prevented from playing the digital content, or the playback device is the digital content. An optical medium configured to decode and allow the digital content to be output at either the highest quality of the digital content or a degraded quality lower than the highest quality of the digital content. 光媒体であって、 暗号化されたデジタルコンテンツと、 前記暗号化されたデジタルコンテンツに対応するデータ処理コマンドとを、含み、 前記データ処理コマンドは、再生デバイスのコンピュータ言語インタプリタによって実行されると、前記コンピュータ言語インタプリタが、前記再生デバイスに対してクエリを行い、暗号キーを用いて暗号計算を実行し、前記暗号計算の結果を取得し、 前記暗号計算の結果を含む、前記再生デバイスのセキュリティデータを受け取り、 前記セキュリティデータを分析して、前記暗号計算の結果と所定値とを比較することで、前記再生デバイスによる再生中に前記デジタルコンテンツが改ざんされるリスクを評価し、 前記リスク評価に基づいて、 前記再生デバイスが前記デジタルコンテンツを再生できないようにするか、または、 前記再生デバイスが前記デジタルコンテンツを復号し、かつ、前記デジタルコンテンツの最高品質か、前記デジタルコンテンツの該最高品質よりも低い劣化した品質のどちらかで前記デジタルコンテンツを出力できるようにする、ように構成する、光媒体。
- 12A device that controls the reproduction of encrypted digital content, which is an input interface for receiving the encrypted digital content and receiving a data processing command corresponding to the encrypted digital content, and the data processing. The data processing command includes a memory for storing commands, a processor, and a computer language interpreter implemented using the processor and for executing the data processing command stored in the memory. When executed by the computer language interpreter, the computer language interpreterA query is made to the playback device, an encryption calculation is executed using the encryption key, and the result of the encryption calculation is acquired.Including the result of the cryptographic calculation,Receive the security data of the device, analyze the security data,By comparing the result of the cryptographic calculation with the predetermined value,Evaluate the risk that the digital content will be tampered with during playback on the device, and based on the risk assessment, either prevent the device from playing the digital content, or the device will play the digital content. An apparatus configured to decode and allow the digital content to be output at either the highest quality of the digital content or a degraded quality lower than the highest quality of the digital content. 暗号化されたデジタルコンテンツの再生を制御する装置であって、 前記暗号化されたデジタルコンテンツを受け取り、前記暗号化されたデジタルコンテンツに対応するデータ処理コマンドを受け取るための入力インタフェースと、 前記データ処理コマンドを格納するためのメモリと、 プロセッサと、 前記プロセッサを使用して実装され、前記メモリに格納された前記データ処理コマンドを実行するためのコンピュータ言語インタプリタとを、含み、 前記データ処理コマンドは、前記コンピュータ言語インタプリタによって実行されると、前記コンピュータ言語インタプリタが、前記再生デバイスに対してクエリを行い、暗号キーを用いて暗号計算を実行し、前記暗号計算の結果を取得し、前記暗号計算の結果を含む、前記装置のセキュリティデータを受け取り、 前記セキュリティデータを分析して、前記暗号計算の結果と所定値とを比較することで、前記装置での再生中に前記デジタルコンテンツが改ざんされるリスクを評価し、 前記リスク評価に基づいて、 前記装置が前記デジタルコンテンツの再生をできないようにするか、または、 前記装置が前記デジタルコンテンツを復号し、かつ、前記デジタルコンテンツの最高品質か、前記デジタルコンテンツの該最高品質よりも低い劣化した品質のどちらかで前記デジタルコンテンツを出力できるようにする、ように構成する、装置。
- 16
Independent claims5
131 paragraphs, as filed
The present invention generally relates to protecting the distribution of digital content from piracy and other misuse or redistribution.
Various systems have been proposed to protect digital content. In most of these protection schemes, the content is stored on the medium or transmitted over an untrusted communication channel to prevent it from being used or copied illegally. Is encrypted. The decryption algorithm and key are software or hardware modules that are reliable and tamper resistant and are access control rules that specify how the content is used (the rules may be fixed or configurable. ) Is managed by a module designed to perform.
Content protection schemes are generally customized for a particular playback environment. For example, software-only streaming content player anti-piracy systems designed for personal computers lack the security benefits of tamper-resistant hardware, but generally (eg, the user uninstalls the player). You can easily upgrade (such as downloading an updated version from the manufacturer's website). As such, such systems are inferior to hardware-based players in terms of robust security, but should modify the content stream or upgrade their software to users in the event of an attack. The impact of the attack is relatively small because the upgraded security features can be deployed by requesting.
On the other hand, as is well known, the protection method incorporated in the consumer electronic hardware device that reproduces the optical medium is difficult to upgrade. Security challenges include the long life of the optical medium (which hinders backwards incompatible security upgrades) and the lack of a convenient and reliable way to distribute updates to players. And that the player implementation is not standardized. In addition to this, the long life of the playback device and the consumer expectation that any new content can be played on older players makes it extremely difficult to upgrade security. As a result, most consumer electronic devices have little or no copy protection, and the few content protection standards in place for consumer electronic devices are inflexible and updatable. It tends to be a simple and inflexible scheme. FIG. 1 is a diagram showing a typical content protection system of the background technology. The content player 100 includes software that implements the player security policy 110, the decryption code 120, and the player key 130 in the non-volatile program memory 105. These codes and keys check whether the content 150 read from the medium is valid, and if it is valid, decrypt the content and supply the decoding result to the output interface 160. Used by processor 140. Examples of protection systems as illustrated in Figure 1 are the copy control scheme used in digital audio tape, the content scrambling system (CSS) for DVD video protection, and the proposed protection for DVD audio. CPPM scheme and is included.
In the background technique, various different techniques are known as follows.
Access Restriction Policies: In the background technology, a wide variety of access policies and methods for specifying such policies are known. For example, the software protection system disclosed in Patent Document 1 uses a simple authentication code issued by a publisher. On the other hand, Patent Document 2 describes various very complicated access rules related to a huge number of participants. Standards for encoding access policies, such as PolicyMaker and X.509 certificate formats, are also proposed (these are used in content delivery and other applications).
Antivirus software: Methods of detecting and blocking known viruses, such as Trojan horses and other malicious code, are well known in the background art. These methods generally include scanning for known viral attributes, such as known instruction sequences. These programs scan files in various ways, such as scanning files at startup, scanning files on-the-fly, scanning these programs when the programs run, scanning memory, scanning new media. It can be made to work by scanning, scanning network communication, and so on.
Content Protection Systems and DRM: A wide variety of content protection systems (also known as DRM (digital rights management) systems) have been proposed. The DRM system according to the background technology generally distributes the content in an encrypted format, supplies a decryption key to a legitimate purchaser, or executes a decryption process. Many features have been proposed and included in commercial DRM. These features include support for superdistribution (encrypted content can be exchanged between users) and pay-per-use billing (offline pay-as-you-go with notifications over the phone line). (Including), variable billing rate (different amounts are charged based on promotion, number of uses or duration of use, required user processing, user history, etc.), various data types (audio, video, text, software, etc.) Protection, support for different formats, support for different types of playback devices (portable, set-top, hardware-assisted computer-based, software-only, etc.).
Copy protection: There are known ways to prevent copying of software for personal computers, and it has been widely deployed for certain types of software, such as software such as computer games. In these methods, it is possible to bind a software program to a physical medium designed to be difficult to copy (for example, by intentionally incorporating an error or non-standard format that is difficult to duplicate). It is often done. Other copy protection systems include protecting the installation process, for example, by requiring the user to obtain an authorization code from the server. Copy protection may be included in the system during the design phase. In addition, although it can be played back by most players, when trying to copy a medium, copy protection is achieved by performing non-standard encoding on the medium, which cannot be normally copied in most cases (computer software, video cassette). Includes copy protection systems used for tapes and audio CDs). In a copy protection system, its main design challenge is to minimize its impact on legitimate users (ie, it is highly probable to play and is acceptable to the user), while taking unwanted actions as effectively as possible. It is to prevent (that is, to obtain good security).
Cryptographic Functions: A wide variety of basic cryptographic functions are known, such as block ciphers, hash functions, digital signature systems (and other public key systems), and key management systems. ing. For more details on the basic encryption technology, refer to Non-Patent Document 1.
Cryptographic oracle: Block ciphers and other cryptographic features allow you to build a "cryptographic oracle" that applies a secret cryptographic transformation to any externally sourced input message and returns the result. .. Cryptographic oracles can be constructed so that it is computationally impossible for an attacker who knows the oracle's algorithms and protocols to determine the oracle's key. In addition, the number of inputs that can be entered into Oracle can be enormous (for example, 2256 for Oracle built from a 256-bit block cipher), allowing an attacker to respond to a random query. Is unpredictable and cannot be calculated in advance.
Interpreters, emulators, and virtual machines: In the background technology, various interpreted computer languages are known. Some interpreted computer languages, such as Java®, require a compilation process to convert source code into executable or interpretable format. In contrast, most BASIC® interpreters process the source code directly. Some interpreters allow self-correcting code, while others do not. In the background technology, a technology for implementing an interpreter and a technology for emulating an assembly language are known. For example, sophisticated emulators, such as Virtual PC® and SoftWindows®, are programs designed for Microsoft® Windows® and Apple® Mac® computers. Can be operated. VM (Virtual Known for machine) designs, such as those used for Java® and Java® Cards, where VMs interact with native code on a computer or have different memory spaces. It is also known that you can call other VM functions in. (Many Java® implementations provide these features.) Interpretered computer languages are commonly used for applications or where cross-platform compatibility is required. , For example, used to create processor-independent device driver formats. (See, for example, Non-Patent Document 2.) Key Management: A wide variety of methods for assigning and managing cryptographic keys have been proposed. It is known that a device can have a device-specific key, a group key, a public key, a private key, a certificate, and the like. The key can be assigned to, for example, individual devices, selected device groups (eg, as described in Patent Document 3), all devices, and the like. The device can include a variety of different types of keys, including symmetric keys, public keys (eg for authenticating certificates and digital signatures), asymmetric private keys, and the like.
Medium: A medium technology is known that can provide a medium having a large storage capacity, a low manufacturing cost, and excellent durability. Examples of current media technologies include optical disks (CDs, DVDs, etc.), magnetic media, flash memories, and ROMs. New technologies such as holographic memory are also being developed. It is known that a single medium can contain many different types of data. For example, a CD (compact disc), along with a standard Red Book audio track, is a data session for use on a personal computer (including, for example, software, compressed bonus tracks, images, footage, lyrics, etc.). Can be included. A CD for use on a personal computer can contain both the encrypted content and the playback software required to play the content.
Network communication: Advanced data networks, including the Internet, are known. These networks can provide flexible, reliable, high-bandwidth data communications. Networks with physical connections usually offer higher bandwidth, but wireless communication channels are also widespread.
Updatable Security: Creating a security system that is guaranteed to protect against all possible attacks may not actually be possible. Therefore, after an attack, for example, it is desirable to stop using the tampered key to fix the vulnerability and thereby update the security. Security should be updatable, but many deployed and proposed systems lack a mechanism to effectively recover from a wide variety of attacks.
Sandboxing: Sandboxing is the execution of a software program in an environment that is controlled so that the software program has no access to processes that can damage the system. Java® "Virtual Machine" supports sandboxing to allow untrusted applets (such as those downloaded over the Internet) to run.
Security Modules: Many security systems employ removable security modules that allow you to upgrade your security without the hassle and expense of replacing other parts of your system. For example, removable security modules are used in many pay TV (television) systems.
Software Update: Secure by receiving the requested software update, verifying the digital signature or authorization code of the message that validates this update, and running this update (if the signature is valid). Software can be updated. For example, digital audio players are known to be able to receive code updates, check the digital signature or message verification code attached to this update, and update those codes (if valid). There is. How to ensure that updates are applied in the correct order (eg using sequence counters) or fail or fail (eg by reverting to a previous version of the software or launching a special recovery code) There are also known ways to recover from a successful update. It is also known that software updates can be virtually supplied via various distribution mechanisms such as the Internet, optical media, and ROM cartridges. Software updates have been used to prevent pay TV piracy. That is, a code update is delivered to the descrambler along with the signal, and the descrambler applies this new code and successfully executes it to calculate the correct decryption key for the next video segment. These updates are typically used to prevent unauthorized viewing by disabling or even destroying unauthenticated descramblers.
Steganography: Steganography is about hiding information in data. For example, it is known that encrypted data can be placed in the least significant bit of an image or audio recording. An attacker who has acquired this image or recording but does not know the decryption key cannot determine whether the data is hidden or not. This is because the low-order bits often appear randomly, and without a decryption key, the ciphertext generated by a strong encryption algorithm cannot be distinguished from random data.
Anti-tamper: Many methods are known for designing and building attack-resistant devices. Anti-tamper hardware is commonly used in systems where it is desirable to prevent an attacker from reverse engineering the device or extracting the key from the cryptographic module. For example, Wave Systems sells a tamper-resistant microprocessor-based IC (integrated circuit) product called "Embassy," which can be integrated with content players or general-purpose computers to deliver digital content. It is advertised to be used to protect. A method of implementing tamper-resistant software has also been proposed (see, for example, Patent Document 4).
Traitor Tracing: A security breach or attack, typically by tracing back from the key used on an unauthenticated device to the customer's specific device or the device on which the security breach occurred. A traitor tracing scheme has been proposed to identify the source of the.
Watermark: A watermark is a signal embedded in content that can be detected by a dedicated detector, but does not (or does) affect human perception when the content is played. A signal that stops at a minimum). Watermarks embedded in photographs, audio recordings, and images have been used by copyright holders to indicate that copying is not permitted. A "robust" water that is resistant to format conversions (including re-recording from analog output) and can provide different levels of security against attacks intended to remove watermarks. Mark is known. In contrast, "vulnerable" watermarks have little or no resistance to format conversion, but are easier to design and can convey more information.
Although there is no anti-piracy system that can completely prevent all possible attacks, background technology systems provide solvable problems, such as digital-to-digital copying and protected formats to unprotected formats. It does not provide a viable solution to casual piracy using fast ripping. The drawbacks that exist in many systems of background technology include, but are not limited to:
Trust in Common Secrets: Many protection systems require that cryptographic algorithms, keys, and other information needed for decryption be kept secret. Therefore, documenting the decryption process into an open standard document forces the security of the system to be compromised. Also, if a huge number of implementations are possible, an attacker can break the entire scheme by attacking the most vulnerable implementation. (Such attacks have recently occurred on DVD-Video protection systems.) Such systems are useful in a single vendor's closed environment, but cannot be standardized and provide long-term effective security. Does not provide.
Lack of standardization: Content authors are already involved in a variety of incompatible data formats and decryption algorithms. Different content protection systems enable different business models, and authors involved in one model can interfere with security systems that require different models.
Product Type Incompatibility: Many security features cannot be integrated into all product types. For example, a downloadable software-only player for a personal computer cannot include tamper resistant hardware. Similarly, frequent software updates make it difficult to supply to players who lack internet connectivity.
User Interface: Many proposals include complex user interfaces. Security should be invisible to non-harmful users. The user may reject schemes that require explicit user involvement (eg, obtaining or entering an authorization code). In general, consumer electronic devices such as car stereos and video disc players should be easy to use. That's because many users, even if they don't read the material, are afraid of technology, have a handicap such as poor eyesight, or aren't fluent in the language the player supports. Because you have to be satisfied.
Legal Challenge: Some security systems require collaboration with competitors. Such collaborative acts may be illegal under antitrust law.
Deficiency of manufacturer's interests: Manufacturers increase player costs and time to market, prevent the inclusion of legitimate features, or make these products inefficient and undesirable. Will oppose the security features it does. Advances in semiconductor technology have reduced the costs required to implement security systems, but designing and manufacturing hardware with effective tamper resistance remains difficult and costly. is there. Therefore, if the content protection system relies on the manufacturer to implement the system well, these contents will not give the manufacturer who provides a more secure one an advantage in the actual market. The protection system will fail.
Uncertain Security Policy: An effective security system must clarify rules and other decision-making procedures for deciding whether to allow or prevent a particular action requested by a user. In many systems, these rules or procedures are not well defined.
Inflexible Security Policy: Content protection systems should be flexible enough to support different models for different authors, different content types, different legal jurisdictions, different playback environments, and so on. The system should be flexible and not overly complex. Long-term security vulnerabilities: Security systems must be robust and flexible enough to maintain security for long periods of time. Few background technology content protection systems can last for more than a few years as part of a high-profile format, but popular formats are more than 30 years old. You can continue.
Untraceable Attack: In the event of an attack, the system must be able to identify the source of the attack so that it can revoke the compromised (or abused) device and prosecute the perpetrator.
<p num="0033"><patcit num="1"><text>U.S. Pat. No. 4,650,93</text></patcit><patcit num="2"><text>U.S. Pat. No. 5,892,891</text></patcit><patcit num="3"><text>U.S. Pat. No. 5,592,552</text></patcit><patcit num="4"><text>U.S. Pat. No. 5,892,899</text></patcit><patcit num="5"><text>U.S. Pat. No. 4,405,829</text></patcit><patcit num="6"><text>U.S. Pat. No. 5,640,306</text></patcit></p>
<p num="0034"><nplcit num="1"><text>Applied Cryptography by Bruce Schneier</text></nplcit><nplcit num="2"><text>Writing FCode 2.x Programs, Sun Microsystems, 1993, page 5</text></nplcit><nplcit num="3"><text>A. Fiat and M. Naor, "Broadcast Encryption," Advances in Cryptology, Douglas Stinson, editor, p. 480; Springer Verlag, 1993</text></nplcit></p>
<p num="0035"> The present application relates to various embodiments and embodiments of standardizable content protection systems that can be implemented to provide flexible and updatable content protection on a wide variety of interoperable platforms.</p>
<p num="0036"> The present invention provides participants (manufacturers, producers, artists, and / or consumers, etc.) with unparalleled flexibility in making security and functionality decisions.</p><p num="0037"> A typical player that can be used with the system (ie, a device that attempts to decrypt or access protected content) includes several components. The first is a data or medium input interface, such as an optical disk drive input interface. To start playback, the player loads a series of data processing commands from this input interface and uses an interpreter or other execution module to start executing these commands. In this execution environment, it is preferable to provide a Turing-Complete language (a language capable of executing arbitrary algorithms under the conditions of player memory, user interface, and performance limits). From this execution environment, the content can query the player to determine the configuration of the playback environment and perform the encryption process using the player's key. Therefore, it is possible to design the content so that the playback proceeds only on the player whose response to the query satisfies the condition. The creator can also provide restricted playback. For example, less secure platforms can offer CD-quality stereo audio and usually fine images, but more secure platforms can offer more audio channels and higher definition. Images, higher sampling rates, and higher quality compression can be provided. Playback can be maintained under the control of the content's data processing commands, even after playback has begun. An exemplary embodiment is robust and essentially on the fly. Includes the ability to perform fly) water marking. Allowing the content itself to control which data area to play allows information to be embedded in the output by selecting from slightly different output data versions. Analyzing these differences allows you to trace pirated copies back to a particular player.</p><p num="0038"> As content contains and implements its own security policy, attacks that occur can be addressed by designing and publishing new, resistant content. Allowing content to implement its own security policy gives it flexibility, which can also support artist preferences, regional "fair use" regulations, and more. The addition of new player functions can be easily performed by adding new player functions to which the content can be accessed.</p><p num="0039"> From a business perspective, any content protection system can be used to connect content creators with consumer electronics manufacturers with the common goal of providing the best possible security in line with business and operational constraints. Is desirable.</p><p num="0040"> According to the system disclosed herein, the author can determine his / her own security requirements, and whether the content itself should be played in each environment, considering a wide variety of factors. You can execute a policy that determines whether (or how to play). It can also motivate manufacturers to design products that have good security and do not facilitate piracy so that their customers have access to the content as widely as possible.</p>
<figref num="1">It is a figure which shows the media player which used the content protection method of the background technology.</figref><figref num="2">It is a figure which shows the example of the media player which used the content protection method disclosed in this specification.</figref><figref num="3">It is a figure which shows the part concerning the decoding in an exemplary embodiment.</figref>
FIG. 2 is a diagram illustrating an exemplary embodiment of a player using the physical medium 200. The reproduction process is controlled by a processor 210 that can access the medium 200 via the medium interface 205. When the medium 200 is mounted (eg, when the medium is first inserted, or when the system is reinitialized, etc.), the processor 210 first initializes the medium interface and reads the table of contents of the medium. Recognize supported protection systems. The processor then loads the small initial portion of the medium 200 into the execution / data RAM 220.
Processor 210 uses interpreter 215 to initiate the execution of the data processing operation specified by this loaded medium portion. Interpreter 215 provides a set of predetermined data processing operations that can accomplish more complex tasks. The interpreted language is preferably Turing-Complete. Turing-complete programming languages are characterized by the fact that algorithms that can be implemented in one such language can be implemented in any other language of such a language, and their implementation has similar apocalyptic performance. It will have characteristics. Turing Examples of complete programming languages are C (registered trademark), C ++ (registered trademark), BASIC (registered trademark), Fortran (registered trademark), Pascal (registered trademark), and Java (registered trademark). And virtually all assembly languages are included, but not limited to these.
The loaded part proceeds by invoking the procedure call provided by interpreter 215. Execution / Data The initial data loaded in RAM 220 can be relatively small, but the code running on the interpreter 215 can load additional data (including code) from the medium by procedural call. , This allows more complex processing to be performed.
By another procedure call, the content can determine the playback environment configuration 225. Therefore, the content can analyze the characteristics of the playback environment (eg, player type, required user action, etc.) to determine whether playback should proceed. In an exemplary embodiment, if a fixable problem is detected (eg, if the medium includes a security firmware upgrade for the player), these can be addressed. If supported, the content queries the output interface 250, and if supported, to the destination program / device 260 (eg, amplifier, digital speaker, speaker driver, etc.). You can also run queries, check security characteristics, load encryption keys, specify output parameters (for example, if security is not certain, specify degraded output quality), etc. it can. In an exemplary embodiment, the content can also be queried against cryptographic oracle 230, such as oracle external removable security (such as a smart card) to allow security hardware upgrades. It can be implemented in module 235. Oracle can also be implemented on, but is not limited to, the processor 210, other hardware in the player, media, connected devices such as speakers, and so on. Cryptographic Oracle 230 can provide verifiable proof of player ID for the content. The results of the query against Oracle 230 can be used to decrypt subsequent content or code parts, which means that players without a valid key (or key revoked) will not be able to decrypt the content. A strong cryptographic guarantee is provided.
In an exemplary embodiment, the interpreter executes the data processing commands specified by the content within a "sandbox", which can compromise the security of the player. Means no access to cryptographic secrets (like Oracle keys). Sandboxing is useful when not all content is always reliable. For example, an attacker could attempt to create malicious content that attempts to extract an encryption key from a player. (Additional information about typical crypto oracles and the processing of these crypto oracles will be provided later.)
If it is determined that the content should not proceed with playback (for example, if the user is trying to make a copy but the content is configured to prohibit copying), the content will Notify an error and deny the requested action. Alternatively, the content can control the rendering and / or output processing to degrade the output quality and the quality of the rogue copy to make it uninteresting.
If it is determined that the content should proceed with playback, the content is a signal from the player specifying that playback should start from a specific location (eg, a specific track) on the medium. Wait for. Interpreter 215 processes the request using the data processing instructions that were loaded into the data RAM 220 that was executed when the medium was mounted. If it determines that the content should proceed with playback, it uses a procedure call to initiate loading of the encrypted content into media interface 205 from the proper location on media 200. Instruct. The content specifies a valid decryption key and parameters to the bulk decryption module 240, which bulk decryption module 240 has RAM. Extract the encrypted content from 220 (or directly from media interface 205) and decrypt the extracted content. The decrypted content is then fed to the output interface 250, which converts the decrypted content into a suitable analog or digital format for use in the destination program or device 260. While playback is in progress, data processing instructions being processed by interpreter 215 can load new decoding parameters or specify new data blocks to read from medium 200. Upon successful completion of playback, the content can reinitialize RAM 220.
The following sections provide additional information regarding interpreters, playback systems and other embodiments and embodiments.
Dealing with attacks
Anti-piracy systems are widely implemented in software and low-cost consumer electronics, but cannot prevent all possible attacks. The techniques disclosed herein are useful in facilitating mastering new content after an attack so as to substantially thwart the current attack. Professional pirates may continue to seek out and install new circumvention systems, whereas in casual piracy, they are constantly developing attack tools. It will be necessary to try to maintain it, and as a result, it is expected that such piracy will be more difficult than simply purchasing content legally. The next section describes how the techniques described herein can be used to address some typical attacks.
The first category of attacks involves fraudulent activity using uncompromised players. For example, the content can be mastered so that it is possible to copy from the original medium, but not from what was copied. From a copy of such content (for example, detecting changes inserted during the copy process, or comparing the serial number and / or type of the current medium with the original one. If you try to copy (it can be recognized as a copy), the interpreter code can prevent playback. Alternatively, according to the interpreter, the content is played with low fidelity (such as playing stereo audio at a sample rate of 44.1 kHz, even if high sample rate multi-channel audio is available). Can, or warn of additional piracy (Anti-piracy) You can insert warnings) and play it. Therefore, it is possible to analyze the information provided to the interpreter to detect an inappropriate user request from a player in which a security breach has not occurred and deal with it.
The second category of attacks involves tampering with a player's encryption key. If the player's cryptographic key is tampered with, the attacker (at least in theory) emulates the cryptographic oracle and (optionally) falsely responds to a query about the playback environment. It is possible to completely emulate the reproduced playback environment. In the event of such an attack, security can be reestablished by requiring the code interpreted in subsequent content to require at least one encryption key that did not exist on the compromised device. it can. If a particular player model or particular manufacturer is the source of many attacks (for example, due to insufficient security implemented in the player), the author will not be replayed on such platforms (for example, due to insufficient security). Or you can create content (which is played with reduced quality).
The third category of attacks includes the subject of security breaches to specific content pieces, or groups of titles, that contain similar interpreter security code. Such attacks can potentially be mounted by modifying the content itself to bypass security checks or by creating a malicious interpreter tuned to play the target title. Such attacks can be addressed by providing different or better protection software for subsequent content.
The fourth category of attacks involves copying content from protected media into an unprotected format and redistributing that content in a new format. No content protection system can completely prevent such attacks, but the techniques and systems disclosed here track security breaches and trace back to a particular device, revoking that device for subsequent attacks. It provides a powerful and flexible water marking feature that can be used to allow prevention. Since the number of users who actively upload content for piracy is relatively small, identifying and canceling the players of these users can significantly reduce piracy. By selectively skipping a part of the ciphertext, an imperceptible difference can be introduced into the decryption output. For example, in an exemplary embodiment, the content is directed to the decryption module of the player to decrypt and output the first ciphertext portion, and then skip the second ciphertext portion. A 0 "bit watermark can be inserted. In order to insert the "1" bit watermark, the content can instruct the module to skip the first ciphertext part and output the second ciphertext part. Encoding such a sequence of bits can be made using any data available in the interpreter code, including but not limited to player IDs, cryptographic results, user action records, output device information, and so on. You can insert water marks in the content. If a pirated copy of the content is found, the watermark can be analyzed to track this illegal copy and trace back to just one player, so this player can be revoked in a subsequent content release. it can. This feature is useful in law enforcement and courts because it can reliably prove that a particular copy originated from a particular player. Trying to make an illegal copy
Of course, there is no user-friendly anti-piracy system that can reliably prevent all possible attacks in any environment. For example, audio and video can be recorded from an analog output. (Recorders without a watermark detector are available, even if the content has watermarks embedded in it.) Then, the data obtained from the analog output is remastered on a new digital or analog medium to create the original. It can be redistributed without the security function of. Similarly, although the player cannot detect a copy made by a professional pirate who has the equipment necessary to make an exact copy of the medium, the techniques and systems disclosed herein are the medium. Can help prevent cloning of. For example, by checking the disc manufacturer ID attached to the medium for each content, it is possible to guarantee that legitimate or inadvertent duplication equipment is not deceived by pirates. The media type ID can prevent content sold on read-only media from being redistributed on writable media. For players with internet, phone / modem or other network support, the content gets authenticated from the server (for example) to authenticate that the medium is valid before playing (or first playing). be able to. Players with non-volatile storage can also store a table of known-bad media serial numbers, which the content and / or player can query against. It is possible to determine whether the medium has been revoked.
Query and control of playback environment
The content can be configured to determine whether the content itself permits its own decryption. To assist in this determination, the player can provide the content with information about the playback environment. Very limited information (eg, user-requested actions, player models, etc.) may often be sufficient, but with more information about whether the content should proceed with playback. Evaluate with (more informed) More detailed and accurate information is desired so that assessment) can be performed. What information and functionality is provided to the content depends on the player's implementation. The following describes (but is not limited to) some exemplary features and capabilities that can be provided to the content. Please note the following points. That is, for a player built from multiple connected components (eg, output ports, connected output devices, operating system device drivers, security modules, etc.), some or all of the following information may be provided: It can be provided to these connected devices, as well as to the main part of the player, including the interpreter.
Security support information: Security specification version, supported query capabilities, and / or form factor of security module (replaceable hardware, embedded hardware, updatable firmware, ROM firmware, PC software, etc.). (The exemplary cryptographic processing function and playback control / decryption function will be described in detail below.)
Manufacturer Information: Name, ID, Website, Public Key / Certificate, Manufacturing Batch, Date and Time of Manufacture, Region of Manufacture, Country of Manufacture, Manufacturer Address, Technical Support Contact Information, and / or Manufacturer Warranty Information, etc.
Device Information: Production Line, Production Number, Model Number, Firmware / Software Version, Device Public Key / Certificate ID, GPS Location Other Physical Location / Region, Content Support Codec Type, Network / Internet Support Information, Network Address, Device Phone Numbers, IP addresses, watermark support, interpreter performance ratings, security certification ratings, device distributors, device retailers, device firmware factors, and / or security specifications, etc.
User Information: Username, Geographical Region, Country, Address, GPS Location and Other Physical Locations / Regions / Countries, User Phone Numbers, IP Addresses, Email Addresses, Web Addresses, Preferred Languages, Problematic Materials ( Controversial material) tolerances, preferred payment methods / accounts, payment limits, purchase history, and / or privacy preferences, etc.
Media Control: Query media format, writable / non-writable, media serial number, recording device type, recording device owner, recording device serial number, recording device security information, and / or recording device watermark check function, etc. Features also allow reading from, writing to, formatting, testing, and / or ejecting media. Additional features allow access to encryption and other special features supported by a particular media format.
Required user processing: for example, playback, recording recording, conversion to new format, loading to portable device, making first copy, making multiple copies, and / or simultaneous playback / recording recording. The content can also be given the ability to start or modify the requested processing.
Output information: Information about the output port, output port configuration, output port security characteristics, connected devices, output data format, and / or output data quality / resolution, etc. If supported, the content can query the output device directly to get additional information about the device and / or request cryptographic processing. The player may also allow the content to modify these parameters, for example, to specify degraded output if security is inadequate.
Environment: ID / hash / version of other programs and device drivers running on the platform, memory contents or hashes, installed attack detection module version, system scan results for attacks, and / or tamper detection The status of the vessel, etc. According to these functions, the content can also modify the memory, for example, to modify the security weaknesses of other programs.
Time: Date, time, time zone, clock cycle count elapsed, time since last reset, time since manufacture, time since last security upgrade, time since last battery replacement, and / or estimated battery life, etc.
Connectivity: Judging the communication function of the player, checking the current connection status, establishing a network connection, establishing a modem connection, specifying the importance of establishing a network connection, checking / specifying the security characteristics of the connection, sending data, data Receiving, terminating the connection, and / or temporarily suspending the connection, etc.
User Interface: Display User Messages, Display Lyrics, Display Graphic Images, Print Graphic Images, Display Advertising / Promotional Messages, Identify Available User Interface Controls, Get User Input, Use Player Speech Synthesizer Voice playback and / or error notification, etc. to the user who made the interface.
Watermark control: Select the content area to output, select the external watermarking algorithm, control the external watermark detector, and / or check the mark detector status, etc.
Others: Player / playback status information, pay-as-you-go management (eg player-based funding), error handling, end-of-play, secure non-volatile memory support (see below), application of player firmware updates, and / or Starting external modules (dynamically linked libraries, etc.), etc.
Some feature and parameter standardizations guarantee interoperability across multiple implementations (for example, so that the content can work effectively in a player environment designed after the content was first announced). And there are some useful to simplify the task of authoring secure content. Standardization is particularly useful in features where products from different manufacturers must provide the same type of information or processing. For example, to allow content to determine the player's form factor (home audio / video, portable, automotive, personal computer software only, hardware-assisted personal computer software, professional studios, movie theaters, etc.) Functions and response codes can be standardized. The advantage of standardization is that it prevents manufacturers from trying to circumvent security controls by notifying information related to related risks in a non-standard format that existing content does not understand.
Of course, the system can also be configured to allow manufacturers to add their own proprietary features to allow content creators to select and use their own (proprietary) additional features. The ability to add new features is of particular value to manufacturers seeking to add new features to their products. This is because these manufacturers can add and support these new features and establish business collaboration with content creators. Such embodiments can be easily extended while maintaining backward compatibility (if necessary).
The manufacturer is responsible for providing accurate information to the content. Content generally cannot directly verify the accuracy of most of the information it receives, but if the manufacturer has a strong motivation to ensure that this information is correct. However, such verification is not strictly necessary. For example, the creator can prevent future content from being played on products made by dishonest manufacturers.
It would be beneficial if the player itself provided cryptographic authentication of the information that the player provided to the content (eg, by including a digital signature issued using a guaranteed player or manufacturer key). Authentication is not essential for most data. Harm disguised as a trusted device in an output device (eg, a digital speaker that requires high quality digital audio data), or in other parts of the system connected via a potentially unreliable interface. Cryptographic authentication becomes more important in order to detect and evade malicious devices. Encryption process
In addition to providing information that describes the playback environment, the exemplary player also implements an encryption process that allows the content to be invoked. This process can behave like a cryptographic oracle, feeding the content input data (eg, a 64-bit plaintext block) and returning the result of the cryptographic calculation. In an exemplary embodiment, the input to the cryptographic calculation includes at least a key (its value is usually unknown and the content is inaccessible) and the input data specified for the content.
The following is an example of the basic elements of encryption that can be provided to the content for the purpose of authenticating the playback environment, extracting the content decryption key, etc., but the above use is limited to the above example. The basic elements of encryption are not limited to the following.
Block cipher oracle: The oracle uses the private key to encrypt (or decrypt) the input message, resulting in a ciphertext (or plaintext).
Hash function Oracle: Hash the input message typically with a private key (using an algorithm like HMAC-SHA, for example) to get the result.
Digital Signature Oracle: Digitally sign an input message with a private key to get the result. This feature can also provide the content with a public key and its certificate.
Random number generators: Random number generators can provide unpredictable information to content, for example, to prevent replay attacks on online connections.
Mathematical Functions: Basic math operations can be provided to help the content optimize its computational process. For example, the content can use an optimized modular multiplication or power function to execute the RSA algorithm of Patent Document 5 to generate / authenticate digital signatures and encrypt / decrypt messages.
The basic element of optimized encryption: Optimizing and implementing standard encryption algorithms can help improve performance. These processes can be used to assist in decoding or hashing a data block, such as an interpreted code space or sector area of content loaded from a medium, but in said data block. What is included is not limited to the above example.
Decryption control: If the content decides to allow playback, the interpreter code can initialize the content decryption module with the correct decryption key for each segment of the content. In addition, the interpreter code can specify parts of the content that should be rendered or skipped (eg, to allow real-time watermark insertion during playback). Key changes (or skip areas) can be specified in advance to ensure synchronization between the interpreter and content streaming from the medium, and then signals in the content can trigger such changes. For example, in an exemplary embodiment, the content specifies a 64-bit value that causes a key change when a ciphertext is encountered, the number of bytes in the ciphertext to skip after the key change, and a new key value to use. be able to.
Key management: Content can use these features to determine which key the player is aware of.
In an exemplary embodiment of the crypto oracle, in which the processing of the crypto oracle does not incorporate random parameters or other variable data, the system will produce expected results for certain inputs. Can be configured to be pre-computed (eg, when the content is mastered). The author can then pass the selected input to the oracle and then program the content to confirm that the expected results have been obtained. A malicious player without a legitimate encryption key cannot calculate the correct oracle response. The number of possible Oracle inputs is enormous (for example, 2128 for Oracle with a block cipher with a block size of 128 bits), so an attacker could pre-calculate the results for all possible queries. It is virtually impossible to save.
In addition to identifying valid players, cryptographic oracles can also be used to identify invalid players. For example, if a key extracted from a legitimate player is used for a fraudulent purpose, the content can be mastered so that it refuses to be played on a player that contains a revoked oracle. Unauthenticated players are likely to contain stolen keys, as content will not play without a valid key. However, when these stolen keys are used, unauthenticated devices expose their status to new content that is aware of the compromise.
A wide variety of methods can be employed to incorporate Oracle results or to check if a particular Oracle query response is valid. The easiest way is to simply compare it to the predicted value. Content fails because this method (at least in theory) can be circumvented by an interpreter that is maliciously designed to behave in a way that all matches the expected values. It can include anticipatory "dummy" comparisons and other tests designed to interfere with malicious interpreters. Oracle itself can also be used to decrypt the code or influence the self-correcting code. For example, the input to the oracle can be an encrypted version of the desired code. Therefore, such an oracle, depending on its configuration, allows content creators to include in the medium code that can only be decrypted by an authenticated player or a subset of players, thereby potentially attacking the code of the content. Helps keep you away from others. Another way to use oracles is to use the output of these oracles as encryption keys or retrieve the keys. These keys can be used, for example, to decrypt code, content, other keys, and various other data. With this flexible decryption feature, a wide variety of protocols and policies can be implemented in the content. For example, if the player has a sufficient variety of keys, the content can be programmed to use a scheme such as the Fiat and Naor method (see Non-Patent Document 3). Even an elaborate access restriction system, for example, the system described in Patent Document 2, has a user interface, a network, data storage, and an encryption function required by the player if necessary (of course, the system is provided with an encryption function. If), it can be implemented.
Access to Oracle input / output pairs can be beneficial to authors in mastering content. If Oracle uses the private key of an asymmetric cryptosystem such as RSA, the author simply obtains the public key and uses it to perform the reverse of the Oracle process. For symmetric oracles built using block ciphers, the player manufacturer can calculate the inverse of the symmetric oracle offered in each player for the creator. For example, if Player Oracle uses a block cipher to decrypt a 256-bit data block with a private key, the manufacturer can give the creator access to the corresponding cryptographic features. Even if you can access the reverse oracle, you cannot tamper with the oracle, so if you are a manufacturer (for example), you can use SSL with a publicly accessible web server to use the reverse oracle. It is also possible to perform calculations. The manufacturer may also provide the producer with an output from randomly selected Oracle inputs. (Manufacturers can provide creators with real oracle features, such as those implemented in players, but these features potentially build rogue players that emulate legitimate players. May be abused by.)
The specific method used to assign keys to players and manufacturers depends on their respective embodiments and security objectives. For example, in one exemplary embodiment, the player is a (pseudo) randomly selected player symmetric key from a large global pool of player symmetric keys, player-specific (pseudo) randomly generated by the manufacturer. Various symmetry including symmetry key, symmetry key specific to the manufacturer, player model, etc., and / or symmetry key that certifies that the player does not have a specific property (for example, not manufactured by a specific manufacturer). A cryptographic Oracle key is assigned, but what is included in this symmetric cryptographic Oracle key is not limited to the above. In this exemplary embodiment, the content can call another function that returns a list of supported keys to identify which key is implemented in the player. The player can also include asymmetric keys. For example, in the above exemplary embodiment, the player has a player-specific public key / private key pair, a player certificate issued by the manufacturer signing the player public key using his or her private key, manufacturing. Certificate issued by the root key issuer that authenticates the vendor's public key, the public key used to authenticate the player's request for access to secure memory areas (see below), and / or player firmware updates Has a public key used to authenticate the version.
In infrastructures involving multiple player manufacturers, it may be useful to have one or more central administrative organizations manage the keys of players, manufacturers, and so on. The central administrator ensures that the minimum security standards are met, that the player provides accurate information in the content code, and that the keys for the new manufacturer (these manufacturer's products are old). It can also be useful in terms of keeping (to make the content playable), tracking tampered keys, performing cryptographic Oracle processing of the content creator, and so on. Secure memory and counter
The memory available to the content is typically volatile, providing the content with a "clean" execution environment each time it is booted. However, for some features it is useful for the content to be able to store data between playbacks and between titles. To satisfy this need, the player can provide the content with storage that is secure, non-volatile storage and that maintains a state between replays. Such storage can require additional security protection to ensure that only legitimate interpreted code can read or modify the contents of the non-volatile memory. Guaranteeing the security of the non-volatile memory is important to the author because, for example, the non-volatile memory can be trusted when tracing offline pay-as-you-go viewing history for later billing. It is not enough to have a key on the medium to unlock each memory slot. This is because such keys are quickly discovered by pirates and tamper with the memory slots of all players. Therefore, in one embodiment, explicit cryptographic authentication of the code accessing these secure non-volatile memory areas is provided.
In this embodiment, the player includes several non-volatile memory blocks, which are locked by default (ie, read and write permissions are not granted). The player also includes a public key used to authenticate the request to unlock the memory block. To access this memory block, the content calls a function that receives a digital signature as input through a block of code that is allowed access to the memory. This digital signature can be authenticated using the public key built into the player, specifies the memory block to unlock, and the access rights granted in each part of the block (any read, any). Write, increment, decrement, zeroize, etc.). The interpreter verifies the digital signature and, if this signature is valid, unlocks the memory and executes the digitally signed code. The following is an example of this process that can be used for regular (eg, monthly) auditing and billing for offline pay-as-you-go content.
(a) Creator X negotiates with player manufacturer Y about the right to control the 4-byte counter in Y's player's non-volatile memory.
(b) Author X writes a function for an interpreter that checks the contents of memory. If the checked value does not reach the consumption limit, this function increments the counter. If not, this feature establishes an internet connection with the creator and makes a payment request that includes counter values, random numbers, and payment information (such as a credit card number or other source of funding stored in the player). To transmit. If the creator accepts a payment that is the past purchase indicated by this counter plus the current purchase, the creator transmits to the player a cryptographic certificate to clear this counter, and the player Check this and set the counter to zero (if enabled). The player locks this memory again and returns a code indicating success or failure to terminate.
(c) Player manufacturer Y digitally signs the memory update code using parameters indicating the memory area, access authority, etc. of creator X.
(d) Creator X creates content containing the signed code and distributes it to the user.
(e) When this user's player begins loading the content, this user is presented with a purchase choice. If this user declines the purchase, playback will not proceed.
(f) The content calls the memory unlock function using the pointer to the code written in step (b) and the digital signature generated in step (c).
(g) This memory unlock function attempts to execute the purchase and notifies the success or failure as described in step (b).
(h) If the purchase is successful, the content will be played for this user. If not, playback ends.
Of course, it is also possible to employ a more elaborate purchasing mechanism using the secure counter mechanism described above. The only real constraints on what can be implemented in content are those that come from the capabilities of the player and those that come from the creativity of the creator.
Various storage techniques including flash memory, magnetic storage devices (eg, hard disks), RAM with battery backup, etc. can be employed in the systems and techniques disclosed herein, but are included in these various storage techniques. Are not limited to the above. (In the background technology, a wide variety of methods are known to provide non-volatile storage, yet to encrypt or otherwise protect such storage.) Secure storage can be located outside the player. Yes (but not limited to this example), for example, in removable modules (smart cards, etc.), in connected output peripherals (speakers, displays, remote devices in home networks, etc.), computer networks Can be located remotely via (but not limited to these examples). Memory block allocation can be done, for example, based on available space, can be guaranteed (eg by slot number), or can be allocated / recycled based on priority. If the memory slot is cleared or opened, unannounced pay-as-you-go viewing records may be lost, so content can be given the ability to specify conditions that can overwrite the slot. For players that can play multiple titles at the same time, but have only one set of non-volatile memory slots, to ensure that the slot modified by one part of the content is accessed by another part of the content. In addition, a locking mechanism may be required.
In one embodiment, the consumer purchases a prepaid smart card and inserts it into a player's slot. This prepaid smart card includes a plurality of WOM (write once memory) slots, and the player can write the content ID corresponding to the title of the pay-as-you-go content in these WOMs. Once the content ID is written, this content ID is incorporated into the cryptographic oracle operation implemented on the prepaid smart card. Therefore, the content can be confirmed to have been purchased by confirming the existence of the correct oracle before permitting playback.
Note that the general approach described above for authenticating player function calls is not limited to use with secure counters. For example, the same approach can protect access to special player features that are only available to authorized authors. Because this approach provides a versatile but extremely flexible way to protect access to computing functions, it also has applicability separate from the techniques and other aspects of the system disclosed herein. Have. Cryptographic-based security features vs. language-based security features
Security policies can be implemented in a number of different ways. Encryption protection allows content to be constructed so that a player who is revoked or unauthenticated does not have the encryption key needed to decrypt the content. Unauthenticated players will not be able to access content that does not have a key (if proper cryptography is used, of course). This approach is relatively flexible. This approach provides content owners with only the ability to block playback on a particular device (in more sophisticated embodiments, using different key sets, how many. Although fine-grained control is possible, key-based control is inflexible in solving more complex access control challenges). Nevertheless, it is extremely effective in dealing with cases where the security of a specific player is compromised or other cases where it is determined that the content is unreliable and therefore the function of decrypting the content cannot be provided.
Language-based controls, on the other hand, provide a very sophisticated security policy that is ineffective in cases where the player's security is compromised (or otherwise totally untrustworthy). can do. As mentioned above, the content can analyze the playback environment and call the cryptographic oracle, and if the result is not satisfactory, it can refuse to play. This approach has virtually unlimited flexibility, so some authors want to block the content for certain content, although it is a player who usually behaves with the following risks: It is very suitable for managing the risk associated with playback on a player that can support processing (such as ripping to an unprotected format). Attackers can, at least in theory, analyze and destroy individual pieces of content (especially if the content code is incompletely written), but generalize these attacks. Is not possible, and with careful use of cryptographic oracles, it can be reliably addressed. In addition, according to the decryption control features described herein, authors who see their content being pirated will identify the compromised device and create new content that is less likely to be attacked. can do. Deployment It is desirable to provide content owners with a long-term secure delivery infrastructure. Earlier content protection systems have failed in this regard. That is, the implementer may initially spare no effort in security to convince the content owner to adapt to the new format, but once the format is successful, security The level tends to drop significantly. Various factors can be considered for this decrease. For example, more implementations can be attacked (more likely products are easily destroyed), and the need for piracy increases as more protected content becomes available. Includes being, and being more sophisticated in the attack. In exemplary embodiments of the systems and techniques disclosed herein, content owners will continue to see how their content is protected, even after the media format has been standardized. Can be configured to allow for virtually unlimited updates so that security is not permanently lost if an attack is discovered.
If the security policy is not static, the manufacturer will remain motivated to provide effective security for a long period of time. For example, content owners may have the ability to block (or block high quality playback) playback on devices whose keys have been tampered with or on products commonly used for piracy. As a result, unlike traditional systems, product manufacturers cannot sacrifice security when competing to offer their products at the lowest possible price. Consumers also want such products, because products with robust security provide the best and most reliable playback experience.
Even a harmless manufacturer can mistakenly manufacture a product that later turns out to be a security flaw. Therefore, we disclose various methods that can be used to address security breaches and security vulnerabilities. For example, a player's cryptographic key and software can be updated using a digitally signed code or updated version of the key. These updates can be supplied to the player in a medium containing software that updates the keys. For example, if a legitimate user's player is revoked due to a security breach for the previous owner, the new owner will contact the technical support desk for the product and obtain a new key. Can be obtained (of course, customer service personnel can discourage pirates from asking for new keys for fraudulent use, such as user information, such as name, address, credit card number. , Phone number, e-mail address, IP address, etc.). The updated version can also be delivered via the Internet (other network connections), modem calls, remote control or keyboard input. Of course, the updated version must be encrypted as securely as possible to prevent an attacker from using the update process to enter a tampered key or otherwise attack the player.
Another way manufacturers can mitigate the effects of security breaches is to include removable security modules, such as smart cards. Including this smart card will implement some or all of Cryptographic Oracle, as well as other security-related features provided to the content. In the event of a security breach, or if a security flaw is found, the smart card can be replaced instead of replacing or upgrading the entire player. It should be noted that simply providing a smart card slot may not be sufficient without a smart card until security is required. To prevent a smart card from being removed from a legitimate player and used by a malicious player, cryptography is used between the smart card and its recipient before the player and / or smart card is sent to the consumer. Can be linked (eg, by having the card and recipient share a symmetric key). Mastering and DRM
It's no wonder content owners are interested in the new costs associated with content mastering. The techniques and systems disclosed herein can be arranged so that the mastering process does not incur significant additional costs by adopting simple security measures. Developing content that complies with complex security policies certainly requires more effort for development and testing, but the choice is entirely optional. (Other protection systems eliminate such choices and force all content creators to use the same security systems, policies, etc.)
Of course, the creator does not have to develop the security system itself. This is because, in the systems and techniques disclosed herein, a third party DRM supplier may provide security modules and mastering systems. These vendors show the best features, the best security, the lowest cost, the best flexibility, the best ease of use, the best performance, the smallest code size, the most extensible undo list, and more. And try to get the creator's business. Techniques and systems disclosed herein beam can be content owners as a platform if it has the ability to determine its own security functions. Water marking and tracking of security breaches
For most conventional water marking methods, the mark detection process is standardized and implemented in a large number of widely deployed products. The static algorithm of this idiomatic water marking method is unfortunately significant because knowledge of such detection algorithms generally allows an attacker to remove the watermark without significantly degrading the quality of the content. You will bear the risk. In an exemplary embodiment, the systems and techniques disclosed herein carry out a general mark removal attack because the mark format, coding process, and detection process are all chosen by the author. Can include on-the-fly water mark insertion, which is difficult to receive.
In one exemplary embodiment, the creator (strictly speaking, a control program created by the creator) attempts to embed some information in the output content. Each bit of this information can be encoded depending on whether the first content portion or the second content portion is decoded and output. These parts can be different encrypted areas on the medium and can be encrypted with different keys. The differences between these parts can be selected by the creator as the content is mastered, ranging from unnoticed minor changes to completely different ones. Since there is no predetermined relationship between these two parts, a pirate who knows only one part (including the decryption key for that part) cannot identify the other.
Cryptographic-based control and program-based control can be used to choose which region to decrypt, so an attacker cannot determine what is in the alternative region. In fact, when designing content, for example, you can encrypt the control code (so that different players use different codes) and include a dummy area that no player can decrypt or only a very small number of players can decrypt. , Attackers can be designed so that they cannot even identify the existence of alternative areas.
In one exemplary embodiment, only a subset of all players have the keys needed to decrypt each version of the content area, but substantially all players have the content area. The content is authored so that it has the key needed to decrypt at least one version of. Therefore, the creator can identify information about the attacker by analyzing unauthorized copies in this area. This means that even if an attacker manages to analyze a (vulnerable to attack) program and decrypt multiple alternative regions, which version is still decrypted from the resulting combination of regions. Please note that this is also the case, as it will be obvious to the creator. After all, the only reliable way users can prevent their ID (or their player's ID) from being revealed to the creator's anti-piracy enforcement expert. In the first place, do not get involved in piracy.
This general marking approach, unlike conventional water marking, does not require standardization of the mark detection process. These differences significantly improve security. In fact, there are no signs that this marking scheme will be attacked. Furthermore, since the watermarked bits have different outputs, these watermarks can be extremely robust and can withstand digital / analog conversion, editing, format conversion, malicious attacks, etc. Can be designed as
It is typically up to the creator to decide how to configure and use the features that mark the content. Some artists will try to prevent the water marking feature from being used in their work and avoid the technique of making any modifications to any small thing. Alternatively, some content is a good candidate for very active use of the marking feature due to the widespread piracy of this content. The selection of parts is usually made so that there is only an imperceptible difference, but which alternative version to choose and code, how to choose from the possible output versions, and these The management of the decryption key of the part is controlled by the content. Since the marking function is controlled by a data processing instruction integrated with the content, this technology implements other functions, such as a prize race in which the winning player prints a congratulatory game, for an inadequately secured player. It can also be used for functions such as delivering security warnings to users who have it and providing bonus content to certain users. The example of such a function is not limited to the above.
Of course, other water marking schemes can also be used in the techniques and systems disclosed herein. For example, either by the code of the content or by an external circuit for watermark embedding (which may or may not be controlled by the content) (mark detection algorithm is standardized). Traditional watermarks can also be embedded in the output. Similarly, detecting a watermark from incoming content and, for example, attempting to make an unauthorized copy or introduce malicious content (again, the code for that content or an external detector). Can be detected (by either). The choice of what watermark to embed and how to respond to the detected watermark can be made within the player and / or within the content. Example of migration process: CD audio
The vast majority of digital content is today delivered unprotected or with minimal protection. For example, the CD audio standard does not include anti-piracy capabilities, and DVD video protection schemes have been extensively breached. Traditional media players do not support sufficient security and need to be upgraded or replaced. The success of a new security system depends on the ability to establish a large number of compatible players.
The techniques and systems disclosed herein can be combined with existing methods for producing copy-protected CDs to produce backwards compatible CDs. Such CDs use non-standard CD formats to create discs that play well on most audio CD players, but confuse computer-based ripping software. Authorized (eg, licensed) personal computer software can also play these discs by correcting inaccurate readings or other parts that confuse the computer. As a result, (most) older audio players can play non-standard (copy-protected) redbook audio parts, which can be played (eg, included on a CD or on the Internet). It can also be played on a personal computer with the appropriate player software (which can be downloaded via). Long-term backward compatibility with existing CD audio players may introduce additional security risks, but will facilitate the development of audio players capable of playing new secure formats (eventually). ) Being able to sell content only in that secure format is beneficial as part of a longer-term strategy. Example: HD (High-Definition)-DVD
The copy protection systems used by today's DVD-Video players have been extensively breached. Since millions of DVD players are already on the market and they cannot be upgraded to new copy protection systems, there is an easy way to upgrade the current DVD format without giving up support for these older users. Absent. Fortunately, DVD players already in place only support "standard" definition TVs (eg, 525 scanlines for NTSC, 625 scanlines for PAL, etc.). It is designed and not designed to support higher quality signals in the HDTV (high-definition TV) format. Older players do not support HDTV, so the new security features disclosed herein can be incorporated into DVDs that support HDTV.
In one exemplary embodiment, the player will have a user-accessible media input mechanism (consisting of mechanical trays for one or more discs), which media input mechanism loads the media onto a spindle. , This medium is rotated by a spindle and read using a laser. The data read from this medium is transported to a microprocessor-based circuit that analyzes the disk encoding to determine disk capacity, format type, and security method. If the disc is an outdated (low resolution) DVD that uses traditional security schemes (CSS), the disc will be played using methods well known in the background technology. If the disc is an HD-DVD that uses a programmable security method as disclosed herein, the content security policy program code (data processing instruction) will be loaded from the disc. Performed by the player. The player can optionally support low-density DVDs with improved security, as well as HD-DVDs with traditional protection methods (although extensively). Using a broken security scheme for new content generally has little benefit.) The quality of the output from this DVD player can be controlled by the content. For example, content can be selected to output low resolution output if the player and / or HDTV output device does not provide sufficient security. In this case, the content may (eg) instruct the player to downconvert the HDTV signal to a lower resolution (eg, using a degradation module specially designed for this purpose) or the signal. Supply only the keys needed to decode the low resolution part of the player to the player (do not give the keys needed to the high resolution part), or instruct the player. Additional considerations and variants
In an exemplary embodiment, the content can be customized for a particular player. In this case, the content can only be played on a single player or a small number of players, but code that is not needed to be played on the receiving device does not need to be transmitted. Therefore, this approach is difficult or expensive to send information to the user, or when this sending speed is slow, for example, storage space is limited, or the content is connected to a slow network. This is especially useful if you have to send via. Even so, the content can be queried to the player to confirm that the playback environment is properly secure.
It is useful to require a particular minimum performance standard from the player's interpreter to ensure that playback is not interrupted or distorted.
In an exemplary embodiment, the system and method can be configured such that content can be exchanged between devices. The security characteristics inherent in such exchanges depend on factors such as the ability to communicate online with a trusted (eg, author-controlled) server. The format in which the content is transferred depends on the security policy adhered to by the content and the hardware capabilities of the device. For example, in one embodiment where both devices include a secure interpreter, the sending device is the raw encrypted content (stored in the original medium or encrypted with another key). And, in some cases, the one containing the watermark) is transmitted together with the code for playback control. This playback control code can be customized for the receiving device by the sending device. In another case, the sending device checks whether the security characteristics of the output port and the destination device are acceptable, determines the shared key with the destination device, decrypts the content, and watermarks the water. A mark may be added, the content may be re-encrypted using the shared key, and the re-encrypted content may be transmitted to the destination.
A player with sufficient non-volatile storage can be used to store updatable code called from the interpreter. For example, the player can be configured to always remember the latest security code for a particular author. In this case, if a newer version of the security code is detected, the older version will be updated (for example, after verifying the digital signature on the new code). In this method, the old content can benefit from security updates made on the new content (eg, this method can be achieved using the secure memory method described above). In other embodiments, the content obtains the current date / time from the player and compares the player with the date / time of the latest known security upgrade to include the current security update. Can be requested. In this way, the content can ensure that the player has a sufficiently up-to-date security upgrade version.
In general, content protection systems should avoid playing a visible role in legitimate actions by legitimate users. Nevertheless, some user interface elements are needed, for example, to signal errors or provide information. If the content can be selected from multiple supported output qualities (eg, if the security provided by the player is inadequate, then "old" quality, and if the security is satisfactory. , Etc.), the indicator is useful for informing the user of the output quality. For example, in one embodiment, a green LED (light emitting) controlled by content. diode) indicates that the output is of high quality (ie, security is satisfactory), orange LED indicates poor quality (ie, security is inadequate), and blinking red LED indicates , It can be shown that there is no output because the player has been cancelled. In another embodiment, a short voice or textual notification (if known in the user's language) is provided to notify the security status. The decision to notify and / or use high quality vs. low quality output can be based on other factors, such as the presence and / or absence of robust and / or vulnerable watermarks. If desired, a degraded module can be included in the player (eg, an HDTV signal) so that the content can reduce playback quality (eg, to the quality of older formats) for security or other reasons. Degradation modules can be included to convert to NTSC resolution or to convert high definition multi-channel audio to 2-channel CD quality audio).
If the media interface and the player interpreter have sufficient performance, bulk decoding and watermark embedding can be processed within the interpreter rather than within another decoding module. If the content can decrypt itself directly, there are security benefits, such as ensuring that an attacker does not attack the decryption module. If the interpreter's performance is sufficient, content decompression can be implemented in the interpreter, eliminating the need to standardize a single player Codec type.
Implementations using an interpreter are suitable on platforms that do not have the hardware support specific to the techniques and systems disclosed herein (eg, personal computers), but implement many of the interpreter features on dedicated hardware. That is possible. For some applications, implementing it specifically will reduce functionality but save cost or power consumption.
Embodiments of receiving content in physical media can use virtually any medium format. Optical disks (such as CDs and DVDs) offer high storage densities at low cost, but other storage systems including magnetic media, holographic memory, RAM with battery backup, ROM, EEPROM, and flash memory can also be employed. Other storage systems are not limited to this example. The storage capacity of the medium can be used to store many different types of data, such as information related to the techniques and systems disclosed herein (eg, for various computer platforms). An executable program that implements the decryption method of, content protected using the methods disclosed herein, etc., and data that is not directly related to the techniques and systems disclosed herein (eg, relationships). Includes non-executable programs, unprotected content such as Redbook CD audio, content protected using other security schemes, etc.).
The medium may include a tamper resistant circuit that performs cryptographic operations so that the player can confirm that the medium is not an unauthorized copy. Such a function is easiest to implement on a medium that uses an electrical interface, but an optical medium can also include a cryptographic function. For example, a contactless cryptographic module (eg, a contactless smart card described in Patent Document 6) can be added to or incorporated into an optical disc. Cryptographic medium authentication is preferred, but other authentication mechanisms can be employed instead. For example, common media authentication methods known in the background art include writing the serial number in a difficult-to-copy location (eg, an area that cannot be written using a commercially available recordable medium or drive). A description of the various properties of the original physical medium, including the inclusion of a digitally signed "commentary". Of course, cryptographic mechanisms, even if an attacker discovers a way to compromise the security of existing media, have the following advantages: future media will publish with improved security, but players Offers the advantage of not making any changes to.
Since many consumers have already invested in content in traditional formats, players implementing the techniques and systems disclosed herein may be configured to support these traditional formats. Similarly, different versions of the interpreter may be supported by a particular player. In this case, the player needs to analyze the medium or content to determine the proper security system to use. For example, in the case of a digital video player, this disc is a traditional DVD with CSS (if so, choose a CSS decryption system), or the techniques and systems disclosed herein. You may want to detect if the DVD uses (if so, boot a language-based decryption system). The robust watermark contained in the content can be used to detect whether the content originally protected by the security system has been copied to a format that does not have the original protection. For example, if the content is not allowed to be copied, it will be allowed by a device that encounters a watermark such as the following, that is, a copy in another format (eg, an unprotected format): A watermark can be included to indicate that playback can be rejected (for example) by recognizing that it has not been done.
The techniques and systems disclosed herein can be used with a variety of content types, including audio, still images, video, 3D images, and 3D video. It is not limited to.
Also, the techniques and systems disclosed herein can be implemented in a variety of physical devices. If only one device is responsible for decrypting the content, it is preferred that the security policy be enforced by that device. However, output devices and intermediate processing devices (eg, audio equalizers or mixers) can also benefit from the techniques and systems disclosed herein and / or the techniques and systems disclosed herein. However, it can be profitable to provide a query function that can be used to check security. In one embodiment, a home entertainment server downloads, stores, and manages the content and transfers the content to a properly secured playback device (speakers, headphones, video display, etc.). Connections to these devices are preferably controlled jointly by the techniques and systems disclosed herein and the destination device to be encrypted to prevent content from being stolen during transfer.
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2000196585A | Cites | Japan |
62 members in 9 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 27932301 | United States of America | P | |
| 27932301 | United States of America | P | |
| 60279323 | United States of America | – | |
| 10113363 | United States of America | – | |
| 11336302 | United States of America | A | |
| 11336302 | United States of America | A | |
| 2001279323 | – | – | – |
| 2002113363 | – | – | – |
| US20010279323P | – | – | – |
| US20020113363 | – | – | – |
Members62
| Document | Office | Kind | |
|---|---|---|---|
| US2002141582A1 | United States of America | A1 | |
| WO02079906A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2002307021A1 | Australia | A1 | |
| WO02079906A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1379936A2 | European Patent Office (EPO) | A2 | |
| US2004133794A1 | United States of America | A1 | |
| JP2004532495A | Japan | A | |
| AU2004258523A1 | Australia | A1 | |
| WO2005008385A2 | World Intellectual Property Organization (WIPO) | A2 | |
| EP1379936A4 | European Patent Office (EPO) | A4 | |
| WO2005008385A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1642206A2 | European Patent Office (EPO) | A2 | |
| KR20060031681A | Republic of Korea | A | |
| CN1839375A | China | A | |
| US2007033419A1 | United States of America | A1 | |
| JP2007535718A | Japan | A | |
| US2008037781A1 | United States of America | A1 | |
| US2008049935A1 | United States of America | A1 | |
| US2008101604A1 | United States of America | A1 | |
| US2008130886A1 | United States of America | A1 | |
| US2008133938A1 | United States of America | A1 | |
| US2008137848A1 | United States of America | A1 | |
| EP1942391A1 | European Patent Office (EPO) | A1 | |
| EP1942392A1 | European Patent Office (EPO) | A1 | |
| CN101241735A | China | A | |
| JP2008186571A | Japan | A | |
| JP2008228330A | Japan | A | |
| EP1642206A4 | European Patent Office (EPO) | A4 | |
| HK1116885A1 | Hong Kong, China | A1 | |
| CN101364415A | China | A | |
| CN100504818C | China | C | |
| JP2009266248A | Japan | A | |
| JP2009282525A | Japan | A | |
| AU2004258523B2 | Australia | B2 | |
| AU2010200153A1 | Australia | A1 | |
| US7756272B2 | United States of America | B2 | |
| US7760876B2 | United States of America | B2 | |
| US7778420B2 | United States of America | B2 | |
| JP2011086313A | Japan | A | |
| US7984511B2 | United States of America | B2 | |
| US7987510B2 | United States of America | B2 | |
| US7996913B2 | United States of America | B2 | |
| JP4798935B2 | Japan | B2 | |
| US2011255690A1 | United States of America | A1 | |
| US2011264923A1 | United States of America | A1 | |
| KR101081729B1 | Republic of Korea | B1 | |
| US8055910B2 | United States of America | B2 | |
| EP1379936B1 | European Patent Office (EPO) | B1 | |
| ATE535853T1 | Austria | T1 | |
| US8131646B2 | United States of America | B2 | |
| JP2012110026A | Japan | A | |
| CN101241735B | China | B | |
| EP2557521A2 | European Patent Office (EPO) | A2 | |
| CN101364415B | China | B | |
| EP2570918A1 | European Patent Office (EPO) | A1 | |
| JP5192556B2 | Japan | B2 | |
| JP5302425B2This record | Japan | B2 | |
| US8571993B2 | United States of America | B2 | |
| EP2557521A3 | European Patent Office (EPO) | A3 | |
| US8949624B2 | United States of America | B2 | |
| EP1942391B1 | European Patent Office (EPO) | B1 | |
| EP1642206B1 | European Patent Office (EPO) | B1 |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Written request for registration of change of domicileJAPANESE INTERMEDIATE CODE: R313531S531 | S531 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 5302425
- Publication, DOCDB
- 5302425
- Publication, EPODOC
- JP5302425B
- Application
- 15867
- Application, DOCDB
- 2012015867
- Application, EPODOC
- JP20120015867
Titles2
- Japanese
- 長期にリニューアル可能なセキュリティを提供するコンテンツセキュリティ方法、その装置およびコンピュータ読取可能記憶媒体
- English
- Content security methods that provide long-term renewable security, their devices and computer readable storage media
Classification
- CPC, 25
- H04L9/0891
- G11B20/00086
- G11B20/00166
- G11B20/00173
- G11B20/0021
- G11B20/00246
- G11B20/00659
- G11B20/00818
- G11B20/0084
- G11B20/00884
- H04L9/3247
- H04L2209/603
- H04L2209/608
- H04N5/913
- H04N21/26613
- H04N21/4135
- H04N21/4181
- H04N21/4325
- H04N21/4405
- H04N21/44236
- H04N21/4627
- H04N21/8355
- H04N21/8358
- H04N2005/91335
- H04N2005/91342
- IPC, 24
- H04L9 08
- H04L9 32
- G06F21 62
- G09C5 00
- G06Q50 00
- G06F1 00
- G06Q30 00
- G09C1 00
- G11B20 00
- G11B20 10
- G11B20 12
- G11B27 00
- H04L9 30
- H04N5 91
- H04N5 913
- H04N21 266
- H04N21 41
- H04N21 418
- H04N21 432
- H04N21 4405
- H04N21 442
- H04N21 4627
- H04N21 8355
- H04N21 8358