System and method for protection of digital works
Abstract
A digital work and a system context (or resource information or system resource) are polarized enabling trusted rendering or replay of the digital work without depolarization of the digital content. The digital work includes digital content and resource information. Resource information may include information used by a replay application to format or process the digital content. The digital work and system context are polarized using a polarization scheme which relies on a polarization seed to initialize and customize the polarization. Different types of polarization seeds may be used, including a random number, a user's system's state or characteristic anda dynamic state-based polarization seed based on a dynamic system state or characteristic. <IMAGE>
Term
Projected expiry 28 May 2032.
- Priority
- Filed
- Granted
- Today
- Projected expiry
4 claims: 1 independent, 3 dependent
- 1A computer-readable storage medium that stores a self-protected document (510) embodied as data on a tangible storage medium, the self-protected document (510) being uninterpretable by the device using the system resources of the device. With some protected content (522),Computer,When executed by the device, the system resources of the device are modified so that the protected content can be interpreted as presentation data using the modified system resources.To function as a secret story release part (428),The protected content includes a secret story release engine (528) containing a code instruction, and the protected content is generated by making the plain text content (910) secret story using a secret story method (918), and the protected content is modified. The secrecy method is specific to the plain text content and the data portion (914) and / of the plain text content according to the modified system resource so that it can be interpreted as presentation data only using the system resources. Or a computer-readable storage medium that converts the formal part (916). 有形の記憶媒体上にデータとして具現する自己保護文書(510)を記憶するコンピュータ可読記憶媒体であって、 前記自己保護文書(510)は、 装置により該装置のシステムリソースを用いて解釈不可能である保護コンテンツ(522)と、コンピュータを、前記装置により実行されると、前記装置のシステムリソースを変更して、該変更されたシステムリソースを用いて前記保護コンテンツをプレゼンテーションデータに解釈可能とする秘話解除部(428)として機能させる、コード命令を含む秘話解除エンジン(528)と、 を含み、 前記保護コンテンツは、秘話化方式を用いて平文コンテンツ(910)を秘話化すること(918)により生成され、前記保護コンテンツが前記変更されたシステムリソースを用いてのみプレゼンテーションデータに解釈可能であるように、前記秘話化方式は、前記平文コンテンツに特有であると共に、前記変更されたシステムリソースに従って前記平文コンテンツのデータ部分(914)及び/又は形式部分(916)を変換する、 コンピュータ可読記憶媒体。
166 paragraphs, as filed
The present invention relates to the management of rights to documents and, in particular, allows blind reproduction of confidential electronic works into plaintext presentation data.<u style="single">Computer-readable storage medium for storing self-protecting documents</u>Regarding.
One of the key issues that has prevented the widespread dissemination of electronic documents or works through e-commerce is, at this stage, the intellectual knowledge of content owners when distributing and using these electronic documents or works. The point is that the protection of ownership is not sufficient. Attempts to solve this problem include "Intellectual Ownership Management" (IPRM), "Digital Rights Management" (DPRM), "Intellectual Ownership Management" (IPM), "Rights Management" (RM), and "Digital Rights Management". It is called "Management" (DRM), "Electronic Rights Management" (ECM), etc. At the heart of digital rights management is the fundamental issue of ensuring that only authorized users can work with acquired electronic documents or works. Access to the Content must not result in the distribution or use of the Content in violation of the content owner's claims.
Documents or literary works here are all units of information that are distributed or transferred, such as correspondence documents, books, magazines, journals, newspapers, other documents, software, photographs and other images, audio and Video clips, other multimedia presentations, etc., but not limited to these. The specific format of the document is printed on paper, electronic data on a storage medium, or recorded on various media in other existing formats. Electronic works as used herein are any document, text, audio, multimedia, or other type of work maintained in digital form and playable or interpretable using a device or software program, or any other type of work thereof. It is a part.
In the case of printed documents, the work created by the author is usually handed over to the publisher, where the work is formatted and a large number of copies are printed. These copies are sent by the carrier to the bookstore or other retail store for purchase by the end user.
In the case of printed documents, illegal copying was deterred because the quality of the copies was usually poor and the distribution costs were high. In contrast, electronic documents are extremely easy to copy, modify, and redistribute if they are not protected. Therefore, it is necessary to adopt some method for protecting electronic documents so that illegal copying cannot be easily performed. If such a method is established, even if it is possible to make a hard copy of a printed document and copy it by a conventional method, it will be useful for suppressing copying.
Printed documents cannot be redistributed electronically without taking the step of digitizing the document. This restriction serves as a deterrent. However, in general, electronic documents are allowed under current general purpose computing and communication systems such as local area networks (LANs), intranets, and personal computers, workstations, and other devices connected via the Internet. The reality is that there is no effective way to prevent distribution without receiving. Several attempts have been made to use hardware to prevent unauthorized copying, but this has not been successful.
Two basic methods have been used to solve the document protection problem: secure containers (systems that rely on cryptographic mechanisms) and highly reliable systems.
The encryption mechanism encrypts the document. The encrypted document is then publicly distributed and stored, and finally decrypted privately by an authorized user. Cryptographic mechanisms provide basic forms of protection when delivering documents from document distributors to intended users over public networks and when storing documents on insecure media. Many digital rights management solutions rely on encrypting electronic works and distributing both encrypted messages and decryption keys to consumer systems. Various methods have been used to hide the decryption key from the consumer, but in reality all the necessary information is available to a malicious user to break the protection of the electronic work. Given that modern general purpose computers and consumer operating systems are rarely offered as advanced security mechanisms, this threat is real and obvious.
A "secure container" (or simply an encrypted document) is a method of keeping the content of a document encrypted until a set of authorization conditions meets the requirements and a copyright fee (eg, payment of royalties) is granted. I will provide a. After confirming various conditions and fees with the document provider, the document is published to the user in plain text. Commercial products such as IBM's Cryptolope and InterTrust's Digibox belong to this category. While it is clear that the secure container approach provides a solution that protects documents when delivered over insecure channels, legitimate users obtain plaintext documents and the content owner's copyright. There is no mechanism provided to prevent the document from being used or redistributed in violation of.
Cryptographic mechanisms and secure containers are focused on protecting electronic works when transferring them to authorized users / purchasers. However, electronic works must also be protected from malicious users and malicious software programs in their use. Even if the user is a trusted person, the user's system can be attacked. A prominent problem facing e-commerce of electronic works is to guarantee the protection of the works on the target consumer's device. When the protection of electronic works is compromised, valuable and important information is lost. Today's general-purpose computers and consumer operating systems are complicated by the lack of areas of security and integrity. Protecting a work over its use is a much more complex issue, and most of this issue remains unresolved.
In the "reliable system" approach, the entire system is responsible for preventing unauthorized use and distribution of documents. Building a reliable system usually involves the introduction of new hardware such as secure processors, secure storage devices, and secure interpretation devices. Even in this case, the reliability of all software applications running on a highly reliable system must be guaranteed. Building highly reliable systems that are difficult to change is still a significant challenge to existing technologies, and according to current market trends, open and unreliable systems such as PCs and workstations own the copyright. It has been suggested that it will be the main system used to access the documents. In this sense, existing computing such as PCs and workstations with common operating systems (eg Windows® and UNIX®) and interpretation applications (eg Microsoft Word). The environment is not a reliable system and cannot be trusted without major changes to these structures.
Therefore, although it is possible to have certain reliable components, the user must continue to rely on various unknown and unreliable elements and systems. In such systems, unexpected bugs and weaknesses are often found and exploited, even if they are expected to be safe.
Traditional symmetric and asymmetric encryption methods treat the encrypted message essentially as a binary string. Applying traditional cryptography to documents has some drawbacks. Documents are usually relatively long messages, and encryption of long messages can have a significant impact on the performance of any application that requires decryption of the document before use. More importantly, a document is a formalized message that relies on a suitable interpretation application for viewing, playing, printing, and even editing. In general, encrypting a document destroys the formalized information, so most interpreting applications require the document to be decrypted in clear text before interpretation. Decryption before interpretation creates the possibility of exposing the plaintext document after the decryption step to anyone who wishes to intercept the document.
Management of rights has various problems such as authentication, permission, accounting, payment and monetary settlement, claim of rights, verification of rights, exercise of rights, and protection of documents. Of these, document protection is an important issue. If the user recognizes the rights of the content owner and is allowed to perform special operations on the document (printing, displaying on the screen, playing music, running software, etc.), the document Is usually plain text. That is, it is not encrypted. Simply put, the issue of document protection is to ensure that the rights of the content owner are not violated when the document is in the most dangerous state (stored in clear text on a machine under the control of the user). is there.
Even if a document is securely distributed from a distributor to a user (usually in an encrypted format), the user cannot view or manipulate the document without displaying the document in display data format. Therefore, in order to achieve sufficient protection, it is important to protect the content of the document in a format that is visible to the user at the final stage and is difficult to revert to a usable format.
<p num="0016"> Known methods of electronic document distribution using encryption are processed in several steps, including: First, the user receives the encrypted document. The user then uses his private key (in a public key cryptosystem) to decrypt the data and retrieve the plaintext content of the document. Finally, the plaintext content is passed to an interpreting application that transforms the computer-readable document into a final document that can be displayed on the user's computer screen or printed on a hard copy. The reason for having to interpret plaintext content is that interpreting applications are usually third-party products (Microsoft Word and Adobe Acrobat). This is because it is a Reader (trademark), etc., and the format of the input document is a format peculiar to the product. However, with the conventional document protection method described above, even a previously protected document is dangerous between the second step of decrypting the data into plaintext and the third step of interpreting the content. Put in a state. That is, it has been decrypted and is still stored in plaintext electronic format on the user's computer. Therefore, there is a problem that the document may be easily redistributed without the permission of the content owner, such as when the user is careless or tries to save money.</p><p num="0017"> While not all systems are completely fraud-proof or vulnerable to attack, recent technologies protect electronic works by limiting their use to user-specified physical devices. There is something. With these techniques, the user must provide private or system state information from the system or physical device intended to be used in the interpretation of the electronic work. The system state information is usually defined as system structure information such as a CPU identifier, a device identifier, a NIC identifier, and a drive structure. In these techniques, the electronic content is encrypted using the session key, and then the session key is encrypted using a combination of system state information and the user's credit proof without using the user's encryption key. Next, both the encrypted content and the key are sent to the target repository. In order to use the encrypted work received, the user must contact a reliable authorization entity (usually a remotely located software program). The authorization entity verifies the user's identity and proof of credibility, then uses the system state to decrypt the session key, and finally decrypts the content for use.</p><p num="0018"> Commercial applications such as secure Adobe Acrobat Reader and secure Microsoft Media Player enable the use of electronic works by examining appropriate user credential and licenses in license vouchers. Among the user's proofs of credit are system device identifiers such as CPU identifiers and serial numbers of certain devices. When the user operates on the electronic work, the application checks whether the specified device exists. This ensures that the electronic work is not transmitted to unauthorized users (actually unauthorized devices). The program's checks provide the minimum level of warranty, but this check relies on the security of the secrets present on the user's device. Not only is the encryption key compromised, but the device identifier itself is also particularly vulnerable to fraudulent threats.</p><p num="0019"> Protection methods such as Acrobat Reader and Media Player work by having the interpreting application identify the required device on the user system specified in the license voucher issued for the electronic work. This provides an appropriate level of protection in many situations (ie, when the user is trusted and the interpreting device specified by the user is not vulnerable to attack). The weakness of these methods is based on the assumption that neither cryptographic key protection nor license voucher integrity will be compromised.</p><p num="0020"> These technologies are more than protection technologies in that once the user's identity and credit information, as well as system state information is verified or a license voucher is received, the content is decrypted in clear text and vulnerable to attack. Is an authentication technology. Electronic works are not protected for their use. Further, the user information approach is problematic in that it assumes that the user is sufficiently deterred from disseminating personal information. That is, for a successful user information approach, it must have relentless consequences for users who disclose their personal identities and credit information.</p><p num="0021"> A major drawback of the method of granting permission to a particular device is that it requires the user to leak important information (eg, CPU number or other personal information), which raises concerns about privacy issues. The user voluntarily leaks information (if the user does not want to leak this information, the user's only option is not to receive the electronic work), but without the need for personal information, the electronic on the user's device. It is desirable to provide a protection method that can protect the copyrighted work. It is also desirable to provide a DRM solution that does not depend on cryptographic key protection or license voucher integrity. It is desirable to provide a DRM solution that delays the decryption of electronic content as late as possible.</p><p num="0022"> Therefore, it would be beneficial to provide an electronic document distribution method that eliminates the shortcomings of known systems. If such a method is provided, the user will not be able to obtain the electronic distribution document in a redistributable form during the decryption process and the interpretation process.</p>
<p num="0023"> The self-protection document (SPD) of the present invention can address the above-mentioned drawbacks of the prior art. A self-protecting document is a combination of an encrypted document and an executable code segment that incorporates most of the software required to extract and use the authorization set and the encrypted document, with special hardware and special hardware. You can protect the content of your documents without using software.</p><p num="0024"> SPD systems are divided into content creators (similar to traditional model authors and publishers) and content distributors. The author / publisher decides the right to create and authorize the original document. Next, the distributor customizes the document so that it can be used by various users, and in the process, customizes the user's purchased permission range so that the user does not deviate.</p><p num="0025"> On the user's system, the self-protecting document is decrypted in the final stage. In one embodiment of the present invention, the SPD itself also has various interpretation functions. So with this SPD, you don't have to rely on unreliable (and unauthorized) external applications. In another embodiment, the interface and protocol of the third-party interpreting application are specified to interact with the SPD to increase the reliability of the interpretation.</p><p num="0026"> In one embodiment of the invention, the encrypted document is decrypted by the user system, but at the same time the document is "polarized" by a key that is at least partially dependent on the state of the user system. This secrecy is less secure than the encryption process used for distribution in terms of cryptography, but it is useful for deterring accidental copying. In the present invention, the secret story is released during and after the processing of the interpretation, and as a result, the intermediate form of the document becomes substantially unusable.</p><p num="0027"> In another embodiment of the invention, the method of protecting an electronic work uses a blind conversion function to convert the encrypted electronic work into encrypted presentation data. The caller's electronic content is protected in its original form by not being decrypted. By this method, the interpretation or reproduction application can process the encrypted document into encrypted presentation data without first decrypting the encrypted document. The encrypted presentation data is then decrypted and immediately displayed to the user. This method minimizes the decoding overhead (because pre-interpretation decoding generally consumes more time and resources) and extends the decoding to the final stage of the interpretation process, thereby extending the entire process (both decryption and interpretation). Performance is improved.</p><p num="0028"> Blind conversion or blind computing can be achieved by one of a plurality of methods. Most electronic works contain formal information, which cannot be processed by playback or interpretation applications (conversion functions that convert electronic works into presentation data) during encryption. Any conversion function can be used if the electronic work is encrypted with a format-preserving encryption method. This is particularly useful in that any commercial reproduction or interpretation application can process an encrypted electronic work into encrypted presentation data. In addition, the blind conversion function is a function of the original conversion function. For example, the blind transformation function can be a polynomial function of the original transformation function. Alternatively, both the blind transformation function and the original transformation function can be affine functions that are integer coefficients of any multivariate.</p><p num="0029"> Not all encryption methods are format-preserving encryption methods. Additive cryptography can be used for all document types and all related conversion functions. In some playback or interpretation applications, for some types of documents, the formal information portion may be left in clear text. For other types of documents, all formal information can be encrypted. For certain types of documents, additive encryption methods can be used to encrypt the formal information, and any encryption method can be used to encrypt the content or data portion of the document.</p><p num="0030"> In particular, the coordinate information of the document can be encrypted by using an additive encryption method, which makes it possible to perform some interpretation conversion on the encrypted coordinate data. For example, for special types of documents and token-based documents, there are two places to use encryption methods for format-preserving encryption. That is, one is for the coordinates of a particular token in the document, i.e. position information x and y, and the other is for a dictionary of individual token images. In order to perform a blind transformation on the individual coordinates of a particular token in a document, the initial encryption method must be an additive encryption method. However, the token dictionary can be encrypted by any encryption method.</p><p num="0031"> Information such as the size of the token image may still be leaked from the encrypted token dictionary. If this is a problem (for example, if the token dictionary is small), you can pad the token with some extra bits before encryption. This embedding can result in cryptographic token images of the same size or several fixed sizes. For token-based documents, the token coordinate information in the dictionary may not be encoded. For example, if one wishes to code the coordinates as a Huffman codeword, this situation can be addressed using the same approach used for identifier encryption. Basically, the codewords in the position table are left in plaintext, the codewords in the codeword dictionary are hashed using a one-way hash function, and the corresponding coordinate information is encrypted. When interpreting, the codewords in the position table are first hashed and then used to search for encrypted coordinate information.</p><p num="0032"> In another embodiment of the present invention, the electronic work and the system context (or resource information or system resource) are made secret, and the highly reliable interpretation or reproduction of the electronic work is possible without releasing the secret story of the electronic content. .. In this embodiment, the electronic work is of a type that includes electronic content and resource information. The resource information may include information used by the playback application to format or process the electronic work into presentation data. Resource information may include a collection of system resources available for playback software on a particular system, such as font tables, color palettes, system coordinates and volume settings.</p><p num="0033"> Various types of electronic works can be turned into secret stories. In addition to the common document type electronic works, audio and video electronic works can be made secret. Electronic works and system contexts are typically escorted at the manufacturer's or content owner's location using an esoteric engine. An esoteric engine is a component used to transform an electronic work and system context into their respective esoteric form. The secret talk engine uses a secret talk method that relies on a secret talk seed, which is an element used for initializing and customizing the secret talk engine.</p><p num="0034"> An electronic work can be made into a secret story by using various secret story making methods. For example, stateless secrecy uses a random number as a seed to convert an electronic work into a secluded electronic work. The state-based esoteric scheme uses seeds based on the state or characteristics of the system to convert the electronic work into an esoteric electronic work associated with the system state or trait. The dynamic state-based concealment scheme uses seeds based on the state or characteristics of the dynamic system to transform an electronic work into a concealed electronic work. In this embodiment, the esoteric electronic work is generally equipped with an esoteric engine, which is an encoded electronic work each time the system requests reproduction of the electronic work. And the encoded system context is re-secreted according to a dynamic state-based concealment scheme. The permission-based secrecy method uses a seed based on permission information received from a trusted source to convert an electronic work into a secret story. For added security, the Confidential System Context can be stored on a removable context device, separate from the Confidential Electronic Work. This device needs to be connected to the system before using the electronic work.</p><p num="0035"> Confidential seeds preferably contain information that can be used to associate a particular electronic work with the final end user or final end user system. In general, the owner or distributor selects the type of secreting method used for secreting an electronic work and the type of secreting key to be used according to the value of the electronic work. Like cryptography, confidentiality schemes vary in level of complexity and strength. When an electronic work is ordered, it makes a copy of some of the resource information for that electronic work, called the system context. Select the Confidential Seed to Confidentialize both the electronic work and the system context. Confidential methods different from those used for electronic works may be used for the system context. However, both secretive seeds are the same. Next, the confidentialized electronic work and the confidentialized system context are provided to the user, and the user performs reproduction or interpretation in the reproduction or interpretation system.</p><p num="0036"> Embodiments of the invention that provide formal preservation encryption and reliable interpretation provide protection until the need arises to decrypt the encrypted presentation data into plaintext presentation data. In this embodiment of the invention, the playback application uses the secreted resource information to convert the secreted electronic work into plaintext presentation data.</p><p num="0037"> Even if only the electronic content of the electronic work is kept secret and the resource information is not kept secret, that is, it is left in plain text, the playback application processes the secreted electronic work and makes it secret. It can be presentation data. This means that the secret talk release unit must release the secret talk of the presentation data to make the presentation data in plain text suitable for display or use by the user. If some of the resource information of the electronic work is also confidential according to this, when the playback application converts the confidential electronic work, the playback application uses the confidential system resource information. , Converts confidential electronic works into plain presentation data. All the required resource information may be kept secret, or only a part of it may be kept secret. Playback is blind in that the playback application is not looking at the original non-confidential electronic content.</p><p num="0038"> In this embodiment, the confidentialized system context (resource information) is used to convert the confidentialized electronic work by a playback application to generate plaintext presentation data. The playback application can be any commercial or third party application. The playback application does not need to be customized to release the presentation data, and the engine of the secret story release unit is not required. The playback application acts as a blind playback system (which uses the secreted system resources to process the secreted electronic content) and depends on the type of secrecy that transforms or encodes the electronic work. This associates the ability to play electronic works with software programs with specific resource information and thus protects the content throughout its use.</p><p num="0039"> Unlike a system that uses encryption to protect an electronic work, and finally decrypts the electronic work into plaintext format, and then provides the electronic work to a playback application, a blind playback system is a playback process. Keep the electronic work encoded in a secret form as far as possible (blind playback does not have a clear decryption step). In the blind reproduction system, the secret story of the electronic work itself is not released in plain text. Since the quality of presentation data is generally inferior to that of the original electronic work, even if the presentation data is obtained in plain text format, it cannot be easily converted (if converted) into the original electronic work.</p><p num="0040"> Many different types of electronic works and their resource information can be kept secret and played back in a blind playback system. Electronic works such as documents, texts, audio files, graphic files and video files can be reproduced by the blind reproduction system of the present invention by keeping appropriate resource information secret. The structure and function of the present invention are best understood by reference to the drawings included with this specification.</p>
<figref num="1">It is a top-level block diagram showing a model of electronic document creation and commercial distribution in a safe or unsafe environment.</figref><figref num="2">It is a flowchart which shows the decoding of the protected electronic document by the prior art.</figref><figref num="3">It is a flowchart which shows the decoding of the protected electronic document by the simple embodiment of this invention.</figref><figref num="4">It is a flowchart which shows the decoding of the protected electronic document by the preferred embodiment of this invention.</figref><figref num="5">It is a functional block diagram which shows the data structure of the self-protection document by one Embodiment of this invention.</figref><figref num="6">It is a flowchart which shows the creation and customization of the self-protection document by one Embodiment of this invention.</figref><figref num="7">It is a flowchart which shows the processing to be executed at the time of processing and use of the self-protection document by this Embodiment from the viewpoint of a user.</figref><figref num="8">It is a graph showing a possible path between an uninterpreted / encrypted document and an interpreted / decrypted presentation data.</figref><figref num="9">It is a flowchart which shows the secret story process by this invention which made the document format information into a plain text state for interpretation.</figref><figref num="10">It is a block diagram of the method of format preservation encryption and high reliability interpretation by this invention.</figref><figref num="11">It is a figure which shows a simple example of a document to be tokenized.</figref><figref num="12">It is a figure which shows the token dictionary for the document of FIG.</figref><figref num="13">It is a figure which shows the position table for the document of FIG.</figref><figref num="14">It is a block diagram which shows the generation method of the secret story electronic work and the secret story system resource by this invention.</figref><figref num="15">It is a block diagram which shows the conversion to the image data of the electronic work by the prior art.</figref><figref num="16">It is a block diagram which shows the blind reproduction system of the secret story electronic work by this invention.</figref><figref num="17">It is a block diagram which shows another blind reproduction system of the secret story electronic work by this invention.</figref><figref num="18">It is a block diagram which shows an example of the structure of an electronic document.</figref><figref num="19">It is a figure which shows an example of an electronic document .</figref><figref num="20">It is a figure which shows an example after making the electronic document of FIG. 16 secret story.</figref><figref num="21">It is a block diagram which shows an example of the structure of the resource information or the system context for an electronic document.</figref><figref num="22">It is a block diagram showing an example of a font table.</figref><figref num="23">It is a block diagram after making the font table of FIG. 22 secret.</figref>
Embodiments of the present invention will be described with reference to the drawings. It will be clear that the present invention can be embodied in various forms, some of which can be very different from the forms of the disclosed embodiments. As a result, the specific structural and functional details disclosed herein are only representative and do not limit the scope of the invention.
Figure 1 shows the top-level functional model of a system for electronic distribution of documents. As defined above, these documents include correspondence documents, books, journals, journals, newspapers, other documents, software, audio and video clips, and other multimedia presentations.
The author (or publisher) 110 creates the original content 112 of the document and hands it over to the distributor 114 for distribution. It is possible for the author to distribute the document directly without using others as distributors, but splitting the work as shown in Figure 1 improves efficiency. That's because author / publisher 110 can focus on creating content rather than the mechanical and mundane role played by distributor 114. Furthermore, by sharing the work in this way, the distributor 114 can also collaborate with a large number of authors and publishers (including the author / publisher 110 shown) to save scale. ..
The distributor 114 then passes the converted content 116 to the user 118. In the standard electronic distribution model, the converted content 116 represents an encrypted version of the original content 112. That is, the distributor 114 uses the public key of user 118 to encrypt the original content 112, and the converted content 116 is customized only for a particular user 118. The user 118 can then display the original content 112 by decrypting the converted content 116 using his own private key.
The payment 120 for the content 112 is passed from the user 118 to the distributor 114 via the clearing house 122. The clearing house 122 collects requests from user 118 and from other users who wish to view a particular document. The payment institution 122 also collects payment information such as payment transactions, credit card transactions, and other known electronic payment methods, and sends the collected user's payments to the distributor 114 as a payment batch 124. Of course, the clearing house 122 receives a portion of the user's payment 120 share. Distributor 114 also receives a portion of the payment batch 124 and sends payment 126 (including royalties) to the author and publisher 110. In one embodiment of this scheme, Distributor 114 summarizes and then sends user requests for a particular document. In this way, one document containing the converted content 116 can be generated so that it can be decrypted by all requesting users. This generation method is known in the art.
It also sends accounting message 128 to audit server 130 each time user 118 requests (or uses) a document. Audit server 130 verifies that each request of user 118 matches the document sent by distributor 114. To that end, audit server 130 receives accounting information 131 directly from distributor 114. If a contradiction arises, the contradiction is sent to the clearing house 122 via report 132. This allows the clearing house to coordinate the payment batch 124 to be sent to the distributor 114. Due to the establishment of such an accounting method, this electronic document distribution model has a low probability of fraud, and it can also handle time-dependent licenses whose fees change depending on the usage time or usage. it can.
The model of electronic commerce in the above document shown in Figure 1 is currently in common use. As described in detail below, this model applies equally to the systems and methods described for the distribution of self-protection documents.
Figure 2 shows the steps performed by user 118 (Figure 1) in a prior art system for electronic document distribution. As described above, a cryptographic device is typically used to encrypt the document. These encrypted documents are then publicly distributed and stored for private decryption by authorized users. This format is the basic form of protection when delivering a document from a document distributor to a intended user over a public network or storing the document on an insecure medium.
First, user 118 receives the encrypted document 210 and proceeds to decryption step 212. As is known in the art, decryption step 212 receives user 118's private key. This key is stored locally on the user's computer or is entered by the user as needed. Decoding the document 210 produces plaintext content 216 that is similar to or matches the original content 112 (FIG. 1).
When the plaintext content 216 is passed to the interpretation application 218, this application creates presentation data 220 (ie, a usable version of the original content 112 of the document). Typically, in such a system, the presentation data 220 can be immediately displayed on a video screen, printed as a hard copy, or used for other purposes, depending on the document type.
As explained above, there are document weaknesses in such systems. Plaintext Content 216 may be copied, stored, or assigned to another user without the consent or consent of Distributor 114 or Author / Publisher 110. In addition, there are legitimate users who try to save the license fee by receiving the document in plain text and freely redistributing and using it without considering the ownership of the content owner. As described above, the present invention provides a method in which a user cannot obtain a document in a redistributable form when processing an interpretation in a user system.
Therefore, the systems and methods of the present invention provide another method of processing encrypted documents in the system of user 118. A simple example of this method is shown in FIG.
FIG. 3 is similar to FIG. 2 in that the encrypted document 310 is passed to decryption step 312 (using private key 314) and interpretation application 316 to finally create presentation data 318. However, the protective shell 320 provides a separate protective layer. Since the protection shell 320 is provided, the document 310 can be decrypted and interpreted without making the plaintext content ingestible (interceptable) (as in the plaintext content 216 in FIG. 2). This is achieved by incorporating decoding and interpretation elements in document 310, as described below with reference to FIG. The decryption and interpretation elements to be incorporated are adjusted to limit the user's interaction with the SPD, limiting certain operations (such as saving a document or performing a cut and paste operation), etc., depending on the user's permission.
Figure 4 is a more advanced version. The method of FIG. 4 includes an intermediate "polarizing" step, that is, a simple encryption step, which has been modified to ensure the security of the document after decryption and before interpretation. First, the encrypted document content 410 is passed to the secret story section 412. The secret talk unit 412 receives the user's private key 414 and decrypts the document content 410 through the decryption step 416. At the same time, the secret talk unit 412 receives the secret talk key 418 from the user's system.
The secret story section 412 uses this secret story key 418 to convert the document into a version containing the secret story content 420. All of these operations can be performed openly without the use of protection mechanisms, unless the Confidential Unit 412 remembers the plaintext version of the document between decryption and cryptic processing of the document.
In one embodiment of the present invention, the confidential key 418 represents a combination of data elements extracted from the internal state of the user system. These data elements include date and time, elapsed time since the last keystroke, processor speed and serial number, and other information that can be continually retrieved from the user system. It is convenient to incorporate time-related information in the secret story key 418 so that the content becomes useless even if the secret story content 420 is captured or acquired. This would make it impossible to interpret the confidential document because the system time would change significantly.
Then, again within the protection shell 422, the confidential content 420 is passed to the interpreting application 424. As described above, standard interpretation applications include third-party applications such as Microsoft Word or Adobe Acrobat Reader . However, such an external interpretation application may not be able to handle the confidential content 420. This is because the content, the format code, and the instruction code used on the interpretation processing side are scrambled during the confidential processing.
Therefore, the interpreting application 424 is required to be compatible (or at least fault-tolerant) or must receive the confidential content 420 that the application can handle almost completely. The latter possibility will be described below in connection with FIG.
The output of the interpreting application is the Confidential Presentation Data 426 (Confidential Interpretation Content), which is formatted by the Interpretation Application 424 but is still Confidential and cannot be read by the user as is. The secret talk presentation data 426 is passed to the secret talk release unit 428, and the secret talk release unit receives the secret talk key 418 and restores the original format of the document as presentation data 430 (plaintext interpretation content). In one embodiment of the present invention, this secret talk release function is combined with an interpretation function or a display function. In this case, the confidential presentation data 426 is directly received by the display device. This display device may be separate from the user system and may receive data via a communication channel.
The secret talk key 418 creation, interpretation application 424, and secret talk release step 428 are all components of the protection shell 422. These are program elements that are difficult to change. All computational (or transform) steps performed inside Protected Shell 422 use only local data and do not store temporary data in globally accessible storage media or memory areas. Export only the final explicit results from Protected Shell 422. This method makes it impossible for the user to take a simple method for the purpose of intercepting or using the intermediate data. For example, you will not be able to modify the operating system entry point or steal system resources.
In another embodiment of the invention, the presentation data 430 in FIG. 4 may be either device-independent data or device-dependent data. In the case of the device-independent type, additional processing by a device driver (display driver, printer driver, etc.) is usually required to complete the interpretation processing. For the currently preferred device-independent data, the adaptation correction for each device to the presentation data has already been done (either in the interpreting application 424 or the secret talk release step 428) and the presentation data 430 is output for the purpose. Can be output directly to the device.
The above decoding method described with reference to FIGS. 3 and 4 is realized by the unique document data structure shown in detail in FIG. As described above, certain operations performed by the systems and methods of the invention require highly reliable components. One way to improve the reliability of the invention by using a specific genuine code (unmodified code) is to provide this code with the documentation. Various data components of the self-protection document according to the present invention embodying such a method will be described with reference to FIG.
The document protection problem-solving method according to the present invention is used on the premise that a highly reliable hardware device or software module is not prepared on the user system side. To achieve this, enhance the functionality of the document and make it an active meta-document object. The content owner (ie, the author or publisher) attaches rights information to the document and specifies the type of purpose of use, the required permits and associated fees, and the software module that grants the user permission. The self-protection document (SPD) referred to in the present invention is a combination of a document, related rights, and an additional software module that realizes the exercise of the rights. Content owners' rights are protected by preventing uncontrolled use and distribution of documents that are not permitted by self-protecting documents.
The self-protection document 510 is composed of the following three main functional segments. The executable code segment 512 contains the executable code portion required for the user to use the encrypted document. The rights and authorization segment 514 contains data structures that represent the various access levels granted to different users. Content segment 516 contains encrypted content 116 (Figure 1) that is displayed by the user.
In a preferred embodiment of the invention, the content segment 516 of the SPD 510 is document meta information 518 (information such as document title, format, revision date, etc.), rights label information 520 (copyright display and rights to be displayed with text). And permission information), and protected content 522 (encrypted document itself).
In one embodiment of the invention, the rights and grant segment 514 contains rights information for each licensed user. A list of charges and conditions may be added to each user's rights. For example, a user named John Doe could be given the right to view a particular document and the right to print it only twice for $ 10. In this case, rights and authorization segment 514 identifies John Doe, associates him with two types of rights (display and print rights), and charges and conditions such as price ($ 10) and printing restrictions (twice). specify. Information of other users may be incorporated into the rights and authorization segment 514.
In another embodiment, the rights and authorization segment 514 incorporates only a link to external information that specifies the rights information. In this case, the actual rights and permissions are stored in another location, such as a networked authorization server, and must be queried each time the document is used. This method has the advantage that rights and permissions can be dynamically updated by the content owner. For example, you can raise the price for display or revoke your rights if you detect use in an unauthorized manner.
In either case, it is preferred that the rights and authorization segment 514 be cryptographically signed (which can be achieved by methods known in the art) to prevent unauthorized modification of the specified rights and authorizations. It is also preferable to encrypt the rights and permissions of the user and others so that they cannot directly display them.
Executable code segment 512 (also known as "SPD control") also contains several subsections, each subsection consisting of software modules, at least in part, contained within the executable code segment. In one embodiment of the present invention, a Java® programming language is used for this SPD control. However, in order to realize the present invention, any language can be used regardless of whether it is a platform-independent language or a platform-specific language (interpreter type or compiler).
The exercising unit 524 confirms the user's ID, compares the action requested by the user with the action listed in the right and permission segment 514, and permits or denies the requested action based on the specified right. It is prepared to do. The processing of the exercise unit 524 will be described in detail below with reference to FIG.
The Confidential Engine 526 is also included in the executable code segment 512 in a protected state. This engine reads and confines data according to the state of the system (or other cryptic key), as described above. In a preferred embodiment of the invention, the secrecy engine 526 processes the document before it is stored or decrypted so that the document is not stored in plain text in the user system. The Confidential Engine 526 is protected (ie, cryptographically signed and encrypted) and cannot be modified, reverse engineered, or disassembled.
The corresponding crypt release engine 528 is also included in the executable code segment 512, allowing plaintext presentation data to be generated from the esoteric content (see Figure 4). The secret story release engine contains a set of secure window objects, which is a change prevention interface to the user system's interpretation API (Application Program Interface). Secure window objects are difficult to intercept. This reduces the chances of intercepting or receiving data for the operating system and reconstructing a plaintext document.
The corresponding crypt release engine 528, contained in executable code segment 512, can generate plaintext presentation data from the esoteric content (see Figure 4). Further, the secret talk release engine 528 is a change prevention interface for a logical output device or a physical output device (for example, a user's display device). What is input to the secret story release engine 528 is the secret story presentation data. Therefore, even if the data is intercepted, the plaintext content cannot be obtained unless the secret talk release process that depends on the user's system state or the like is executed.
The secure display unit 530 is optionally incorporated in the executable code segment 512. The secure display unit 530 is used to allow only the permitted access levels based on the rights and permission segment 514. For example, if the user only buys the right to view the document (does not buy the right to save or print), the display does not allow the user to save or print, and the current It also does not allow cut and paste to be performed on most operating systems.
Also, the interpretation engine 532 is included in or referenced by the executable code segment 512. The interpretation engine 532 does not need to be protected. Therefore, the code for the interpretation engine 532 may be embedded within the SPD applet or may be obtained from elsewhere (via a secure link). In both cases, the interpretation engine 532 is set to receive the input of the confidential document content and create the confidential presentation data from the content data (see FIG. 4).
The above aspects and elements of self-protection document 510, along with the operation of the system, are described in detail below.
Figure 6 shows the steps taken when self-protection document 510 is created and distributed. The generic SPD610 does not incorporate user-specific rights information and is not encrypted for a particular user. The generic SPD610 is created from three items: plaintext (unencrypted) original document content 612, high-level entitlement 614, and optional watermark 616.
Content 612 is preprocessed to determine the layout of the document according to the wishes of the author or publisher (step 618). For example, you can select the desired page size, font, and page layout. The content 612 is "pre-interpreted" in the content pre-processing step so that it is in a format compatible with the user system and SPD. For example, content 612 is converted from Microsoft Word (".DOC") or Adobe Acrobat (".PDF") format to another format specifically configured for the interpretation engine 532 to read (Figure 5). In one embodiment of the invention, multiple versions of the content 612 are generated in the content preprocessing step and stored in the general purpose SPD610. Users can purchase these different versions individually on request.
High-level rights designation 614 describes possible combinations of access rights. This rights designation is tailored to each document and can describe different rights groups in different classes of downstream users. For example, a publisher can be entitled to distribute up to 100,000 copies of a document for a fee of $ 1.00 per copy and $ 2.00 for additional copies. Similarly, users can be given options to purchase each version of a document, such as a document that "expires" after a month or a year, or a document that does not expire. Some possible limitations are described with reference to detailed examples. An example will be described below.
The Digital Property Rights Language (DPRL) is the language used to specify the rights of digital works. This language provides the ability to specify various fees and conditions relating to rights and exercise the rights. The designation of rights is expressed as a statement in DPRL. For more information, see US Pat. No. 5,715,403 Granted to Stefik, "System for Controlling the Distribution and Use of Digital Works Having Attached Usage Rights Where the Usage Rights are Defined by a Usage Rights Grammar." Exercise of rights and verification of conditions related to rights are carried out using SPD technology.
Various rights can be specified for each element of a digital work using the "work" designation. In the work specification, various sets of rights applicable to each work can be specified. Rights can be categorized into named groups called "right groups". Each right in the rights group is associated with a set of conditions. There are various types of conditions such as payment fee, usage time, access type, digital watermark type, and device type for processing. DPRL supports various rights categories such as transfer, expression rights, derivative copyrights, file management rights, and composition rights. Transport rights relate to the transfer of copyrighted material from one storage location (repository) to another. The right of expression relates to the printing and display of the work, and more generally to the transmission of the work to external media via a converter (this is the "export" used to make a copy of the plaintext. Rights are also included). Derivative copyright refers to the reuse of a work when creating a new work. File management rights relate to making and restoring backup copies. Also, the configuration right is related to the installation of software in the repository.
An example of DPRL work specification is shown below.
<maths num="1"><img id="000002" he="234" wi="124" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
This work designation has a rights group called "Regular". "Regular" means "Zuke-Zack, It specifies the rights to the standard retail version of the book entitled "the Moby Dog Story." This work specification has some rights conditions such as play, print, transfer, copy, delete, backup, and restore. Represents. The work in this example has two additional components, a photo and a dog chart (chart of), incorporated from other sources. breeds) and are included. The "bundle" designation summarizes a common set of conditions that applies to all rights within a group. This designation means that all rights within the group are valid until January 1, 1998 and the fee will be paid to the account "Jones-PBL SH-18546789". The settlement authority for this transaction is Visa. In addition, the contracts described below apply. You pay $ 1.00 per hour to play the work, and the fees are accumulated in seconds. The work can be printed on the Trusted Printer-6 guaranteed by "DPT" and costs $ 10.00 per print. The printed copy is attached with a watermark string (set as above) and a token list as a "finger print" known at the time of printing. This work can be copied by paying $ 10.00 or by obtaining a Distributor Certificate from Murphy Publishing. Unlimited transfer, deletion, or backup of this work is permitted (restore cost $ 5.00).
High-level entitlement 614 is also subject to the preprocessing step (step 620). In this case, the high-level (human readable) designation is compiled into a more effective data structure representation and in a format that can be used in the present invention.
Next, a general-purpose SPD610 is created by combining the preprocessed content 612, the preprocessed rights designation 614, and the watermark 616 (step 622). The digital watermark can be added by any method known in the art. The digital watermark in the SPD may or may not be visible. The generic SPD610 may optionally be encrypted by the author / publisher 110 and sent to distributor 114 (Figure 1).
Distributor 114 then receives the generic SPD610 and stores it for later customization. When Distributor 114 receives User Request 624 (either directly or through a clearing house 122 or other intermediary agency), Distributor 114 has a user authorization compatible with both User Request 624 and Permission 614. Create a set (step 626). Without such a compatible set of permissions, no further actions are taken for the user (except for the optional notification message to the user).
It then uses the user authorization and the user's public key 628 to generate a customized SPD632 configured for the user to use (step 630). The user permission obtained in step 626 is stored in the rights and permission segment 514 of SPD632, and the content of the content segment 516 of SPD632 is encrypted using the user's public key 628. Here, the public key cryptosystem can be used to convert the SPD from a general-purpose format to a customized SPD632. This mechanism is useful for confidentializing SPDs while protecting rights at each stage between various parties such as authors, publishers, retailers, and customers. In addition, it should be noted that multiple user requests can be created and stored in one SPD632. As this technique, a technique is known in which a document can be encrypted using a plurality of public keys and can be decrypted using an arbitrary user private key.
The resulting custom SPD632 is either transmitted to user 118 by available means such as a computer network, or stored and distributed on a physical medium (magnetic disk, optical disk, etc.).
The operation to be performed when the user receives the SPD is shown in the flow chart of Fig. 7. First, the SPD is received and stored in the user system (step 710). Normally, you don't need to use SPD immediately. When desired to use, the user is usually authenticated first, usually using a username and password or key (step 712). The system then determines the action the user wants (step 714). When an action is selected, the exercise step of the invention (step 716) is performed to inspect the conditions associated with the desired action (fee, time, access level, watermark, or other conditions, etc.). This can be done locally with the executable code SPD applet 512 (Figure 5) or by accessing the rights enforcement server.
If the exercise step (step 716) fails, the update procedure (step 718) is performed. Here the user is given the opportunity to renew their permissions, such as approving additional charges. When the condition inspection is completed normally, the pre-audit procedure (step 718) is executed, and the SPD system records the inspection status in the tracking service (audit server 130, etc. in FIG. 1). This ensures that the content is interpreted as described above and displayed and played back on the screen (step 722). When the user's processing is complete, the post-audit procedure (step 724) is performed and the usage is updated by the tracking service. The SPD system then waits for the next action.
A characteristic of SPD protection is that in the intermediate stages of the interpretation process, the document is not available to the user in a fraudulent form such as redistributing. This is achieved by decrypting the document content as late as possible, preferably in the final step.
Figure 8 shows the SPD decoding model. E indicates the cryptographic function performed by the publisher, D indicates the decryption performed by the user system, and R indicates the interpretation conversion process. In many conventional systems, the first conversion sequence, path 810, that is, D (E (x)) is executed, and then R (D (E (x))) is executed. As mentioned earlier, early decryption puts the document in jeopardy. If possible, the transformation should be in reverse order, route 812, that is, R'(E (x)) followed by D (R'(E (x))). As a result, decoding is performed at a later stage as much as possible.
Whether or not R'is possible, that is, whether or not the interpretation process can be executed before decoding, is determined by the following formula. D (R'(E (x))) = R (D (E (x)))
Here, R'is possible when the encryption function and the decryption function are commutative, that is, when E (D (x)) = D (E (x)) for any x. Whether or not it can be confirmed by the following formula. When y = E (x) R'(y) = E (R (D (y)))
In practice, the encryption and decryption functions of common public key cryptosystems such as RSA systems and ElGamal discrete logarithmic systems satisfy this commutability requirement. That is, if these decryption systems are used for encryption and decryption, the conversion R'is possible.
The path x'= D (R'(E (x))) provides an ideal SPD solution for document protection against unauthorized document use and distribution. The scenario of document distribution and use is described below. When a user purchases a document, the document is encrypted using the user's public key information and sent over an insecure network channel such as the Internet. Rights information is added to the encrypted document, and the content owner grants the user a protective applet 512 that enforces the rights and permissions. When the user requests the use of the document, the applet confirms rights and permissions and generates a presentation format of the original document from the encrypted document. Because any intermediate format of a document before it becomes the final presentation data format is encrypted by the user's confidential information, the document protection SPD model allows other systems to intercept this intermediate format of the document. It is guaranteed that it cannot be used with.
This ideal model depends on whether the conversion process R'corresponding to the interpretation conversion process R can be calculated effectively, in particular whether it is necessary to call the decoding function D when executing R'. It is clear that. A trivial case where R'can be executed effectively and does not have to be a problem is when R is commutative with the cryptographic function E. In this case, for y = E (x), R'(y) = E (R (D (y))) = R (E (D (y))) = R (y). In this case, R'= R.
Figure 8 shows two extreme cases x'= R (D (E (x))), that is, with no protection for x = D (E (x)) and x'= D (R'). Between (E (x))) (ideal protection), there are some intermediate solutions to the document protection problem (eg, intermediate solutions 814, 816, and 818) (the above assumptions). Is to exist (under). As shown in FIG. 8, there are various paths to obtain presentation data x'from the encrypted document E (x), which are partially interpreted and converted. It can be seen that it corresponds to various combinations of data. In this case as well, it can be seen that the protection level of the document is improved by delaying the decryption D in any path.
As described above, the alternative method of delaying the decryption process as much as possible employs a secret story technology that encrypts only the content of the document, not the entire document or format. Figure 9 shows how to achieve this. The document content 910 is initially in clear text (this is not a single point recognizable during user processing, but a temporary state that occurs during step 412 in Figure 4). The document is divided into a data part 914 and a format part 916 (step 912). The data part 914 is made secret using the confidential key 920 (step 918) and merged with the plaintext part 916 (step 922). As a result, the secret story content 924 can be obtained. This confidential content can be interpreted as confidential presentation data without decoding the content. This confidential form is less secure than full-fledged encryption with a secret key. This is because a large amount of information can be obtained from the layout of the document, the length of words, the length of lines, etc., and therefore the outline contents can be clarified. However, this method can deter accidental piracy.
A method of protecting an electronic work during reproduction using a blind conversion function is shown with reference to FIG. In FIG. 10, an encrypted electronic work 1010 is provided for a playback application. The electronic work 1010 is encrypted with a format-preserving encryption method that allows the playback application 1012 to generate encrypted presentation data 1016. Next, the encrypted presentation data 1016 is sent to the decryption engine 1018, where it is decrypted into the plaintext presentation data 1020. The presentation data is now in clear text, but it is unlikely that it will be regenerated into its original digital format. If the user can directly view and use the presentation data 1020, no further processing is required. However, further interpretation may be required depending on the display system such as a printer. In such cases, the presentation data 1020 is provided to a display system interpreting application (in the case of a printer, which can be a decomposer), which produces image data 1024. The image data 1024 is then provided to the display device 1026.
In general, the problem of blind transformation can be described as follows. A client named Cathy wants Steve, a server, to calculate the function value F (a, x) using his (public or private) data a and her private data. And suppose Kathy wants this conversion to happen without Steve knowing her private data x and the function value F (a, x) from a privacy standpoint. From Steve's point of view, this means calculating F (a, x) with the blindfold for Kathy. This is the data E encrypted by Kathy's key k to Steve on the server.<sub>k</sub>Function value E that was converted using only (x) and re-encrypted using her key k<sub>k</sub>It means that I want her to return (F (a, x)). If Steve can perform the conversion process using the encrypted data, Cathy can avoid publishing the data x and the result F (a, x) in clear text. The ideal model for blind transformation using partially encrypted data is shown below.
<maths num="2"><img id="000003" he="64" wi="144" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
The function F'that makes this figure commutative is actually calculated by Steve, and the result of the conversion is F'(a, E).<sub>k</sub>(x)) = E<sub>k</sub>(F (a, x)) is ready to undergo decoding to reveal the desired function value F (a, x). Since Steve does not "see" the plaintext data x and the function value F (a, x), he is doing a "blind" transformation for Kathy.
Regarding the blind evaluation of the function F (a, x), the protocol for blind conversion can be explained as follows. (i) Kathy encrypts x with the encryption key k and E<sub>k</sub>Generate (x) (ii) Cathy is E<sub>k</sub>Send (x) to Steve (iii) Steve is plaintext data a and encrypted data E<sub>k</sub>Evaluate the transformed version F'of the function F in (x) (iv) Steve results in F'(a, E<sub>k</sub>Return (x)) to Kathy (v) Cathy is the decryption key k<sup>-1</sup>Using F'(a, E<sub>k</sub>Decrypt (x)) to get F (a, x)
The ideal model of blind transformation presented here can be viewed as a generalization of blind signatures and instance hiding. Blind transformation allows partially encrypted data as input, and more importantly, the server-calculated function F'can be different from the desired function F. By calculating F'instead of F, the server is still blindfolded, but recognizes that the input is partially encrypted and can therefore cooperate with the client. Blind transformations and secure and flexible calculations have a common goal of keeping the function values calculated by the server secret to the client, whereas in blind transformations the server functions when the client supplies data input. It differs in that it supplies a program to evaluate) and vice versa in safe and flexible calculations. Note that the blind transformation allows some part of the data (eg a) to be in plaintext form. This allows some data in dynamic but still plaintext format to be used for interpretation processing such as display window size, reference position for moving content, magnification and scaling factors in rotation operations.
Blind transformations are only valid if the functions F and F'for computing encrypted data are possible. The affine functions of multivariate integer coefficients using additive cryptography can show that many of the affine-type document interpretation functions on the x and y coordinates can be evaluated by blind transformation. If a function F': X X is possible for a given encryption method S, the function F: X X is said to be "blindly calculated by S". This makes the computational complexity for evaluating F'a polynomial of computational complexity for evaluating F, and F (a, x) = D for any k K and x X.<sup>k-1</sup>(F'(a, E<sub>k</sub>(x))). If the encryption method S is possible, the function F: X X is said to be "blindly computationally possible", and X is a subset of the message space so that S can blindly compute F. ..
Any affine function with multivariate integer coefficients can be blindly calculated by S for any additive cryptosystem.
<maths num="3"><img id="000004" he="50" wi="158" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>Indeed, F'<sub>y0, b1,</sub>...<sub>, bk</sub>Constant y<sub>0</sub>And integer coefficient b<sub>i</sub>Incorporate y<sub>0</sub>= E<sub>k</sub>(x<sub>0</sub>), b<sub>i</sub>= a<sub>i</sub>, i = 1, ..., k. Subject to the theoretical basis of formal preservation encryption and highly reliable interpretation of documents as described herein, by blind transformation of multivariate integer coefficient affine functions using additive encryption schemes. Many of the affine-type document interpretation functions on the x and y coordinates can be evaluated blindly.
A document is usually a message in a fixed format. There are many different ways to encrypt a document, besides simply encrypting the entire document. The goal herein is to make the leakage of information about the unencrypted part unusable, that is, to make it computationally difficult to reconstruct the original plaintext document if the information is leaked. Is.
If the encryption method retains the format information of the electronic work, any conversion function (reproduction application or interpretation application) can be used. An example of a format-preserving encryption method will be described with reference to a token-based document for convenience. Format preservation encryption methods can be easily extended or applied to documents in other formats (eg HTML / XML, Microsoft WORD, Acrobat PDF, etc.). In token-based formats such as Xerox's DigiPaper, each page image of a document is represented as a "dictionary" of token images (such as text and graphic elements) and location information (indicating where the token image appears on the page). .. Therefore, even if the same token appears multiple times in the document, it can be represented by using only one image of the token in the dictionary.
A method of interpreting a document in this format is achieved by continuously reading the position of the token, taking the image of the token from the dictionary, and drawing the image at the specified position. The advantages of token-based documents are their compact file size and fast interpretation when used for distribution, display and printing of electronic documents. In the DigiPaper format, the token is stored as a binary image using the CCITT Group 4 compression format or as a color image using JPEG compression, and the token position information is further compressed using a Huffman code.
For convenience, a token-based document D consisting of P pages, size representing an image of P pages | L<sub>k</sub>| Position L<sub>k</sub>Formally model as a table (dictionary) of tokens T of size | T | with a sequence of P tables (1 i P). Each entry T [j] (1 j | T |) is a set (id [j], t [j]) having the identifier id [j] of the j-th token and the image t [j]. i-th image position table L<sub>i</sub>Each entry in L<sub>i</sub>[k] (1 k | L<sub>i</sub>|) Is a set (id [k], x [k], y [k]) representing the occurrence of the kth token in the ith page image, where id [k] is the identifier and x [ k] and y [k] are the differences between the x and y coordinates from the previous (k-1) th token occurrence in the page. For example, consider the concise document shown in Figure 11. The token dictionary and position table (using x and y coordinates) of this document are shown in FIGS. 12 and 13, respectively.
The schematic pseudo-code Render (D) below shows how to interpret the page image of document D. In this code, x<sub>0</sub>, y<sub>0</sub>Is the base reference for the x and y coordinates for each page, and Lookup (T, id [k]) is the dictionary T and the dictionary T corresponding to the given identifier when the token identifier id [k] is entered. It is a subroutine that returns to the token image in, and Draw (x, y, t) is a subroutine that draws the token image t at the position (x, y).
<maths num="4"><img id="000005" he="207" wi="134" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In addition to the shift transformations x'= x + a, y'= y + b as used in the general interpretation method described above, there are several other coordinate transformations that can occur during the interpretation of the document.
<u style="single">scaling</u> The scaling transformation has the form x'= ax, y'= by, where a and b are the magnifications of the x and y coordinates, respectively. Scaling can occur by resizing the display window or printing paper.
<u style="single">rotation</u><maths num="5"><img id="000006" he="34" wi="158" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
<u style="single">Affine transformation</u> The affine transformation takes the form of x = ax + by + e, y = cx + dy + f for some constants a, b, c, d, e, f.<maths num="6"><img id="000007" he="34" wi="158" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>It is clear that shift transformations, scaling transformations and rotational transformations are special cases of affine transformations. It is these affine-type transformations that can achieve a high level of reliability interpretation in the encryption of coordinate information using the additive encryption method described below.
A special kind of cryptography, or additive cryptography, is used to perform blind transformations of affine-type functions that provide the basis for a highly reliable interpretation of a document. Interpretation transformation of encrypted document The blind transformation by R and R'satisfies the relationship D (R'(E (x))) = R (D (E (x))). In the formula, E is the encryption function and D is the decryption function for E. If E (x) is an additive encryption method, then R'= R.
The encryption method S is generally (i) a message space X which is a collection of possible messages, (ii) an encrypted text space Y which is a collection of possible encrypted messages, and (iii) a key which is a collection of possible keys. From basically five components, such as space K, (iv) computationally efficient encryption function E: K × X Y, and (v) computationally efficient decryption function D: K × Y X. Become. Each key k K unique key k<sup>-1</sup>There is K, which gives the encryption function E<sub>k</sub>= E (k,): X Y and decoding function D<sub>k-1</sub>= D (k<sup>-1</sup>,): Y X is D for each message x X<sub>k-1</sub>= (E<sub>k</sub>(x)) = x is satisfied. The key k is called the encryption key and k<sup>-1</sup>Is called the corresponding decryption key.
The encryption method defined in this way can be modified in several ways to cover a wide range of concrete encryption methods actually used. One variant is to consider whether the keys used for encryption and decryption are different from each other. Decryption key k that all encryption keys k correspond to<sup>-1</sup>If it is the same as, then this method is symmetric (or private key), otherwise it is asymmetric. For all possible k, k<sup>-1</sup>Is different from k, and if it is computationally difficult to derive from k, then this method is public key cryptography.
Another variant is to distinguish between deterministic and probabilistic encryption methods. In the deterministic method, all cryptographic functions E<sub>k</sub>And decoding function D<sub>k-1</sub>Is a decisive function, but in the stochastic method, the encryption function E<sub>k</sub>Can be non-deterministic, i.e., by applying this function twice to a message, two different encrypted messages can be generated.
An additive encryption method has an additive structure with a message space X and an encrypted text space Y, and an encryption function E.<sub>k</sub>= E (k,): X Y is an encryption method that is homomorphic to the additive structure.<maths num="7"><img id="000008" he="76" wi="158" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
<maths num="8"><img id="000009" he="57" wi="158" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
In general, additive (and multiply) encryption methods are not non-adaptive. This is because the non-adaptive method requires that, given an encrypted message, it is not possible (at least computationally) to generate a different encrypted message to which each plaintext message is associated. Because it is done. Therefore, additive encryption methods are vulnerable to active attacks in which an attacker attempts to otherwise delete, add, or modify encrypted messages. However, when these methods are used to encrypt documents, they are added to data integrity and message authentication to reduce the risk posed by these active attacks on document integrity and confidentiality. You can take steps. In addition, these attacks affect the content of the document that the user intends to use and consume, thus reducing the end user's motivation to launch an active attack.
All cryptosystems cannot be easily and naturally defined as additive. In fact, some cryptosystems are designed to be non-additive, or at least convertible to non-additive. However, there are many examples of additional encryption methods that can be used in formal preservation encryption and highly reliable document interpretation methods. Mult, Exp and EG (three definitive methods), OU (stochastic), and RSA are examples of additional encryption methods that can be used for format storage methods (various degrees of attack). ..
Multiplication cryptography (Mult) is a symmetric encryption method, where X = Y = Z for an integer n> 0.<sub>n</sub>= {0,1, ... n-1}. Encryption of message x using key a is y = E<sub>a</sub>(x) = ax (mod n), and decryption of message y using key a is x = D<sub>a</sub>(y) = a<sup>-1</sup>y (mod n), a in the formula<sup>-1</sup>Is the reciprocal of the multiplication of Modulo n.
Exponential cryptography (Exp) is a symmetric cryptography, where X = Z for a prime number p.<sub>p-1</sub>And cryptographic text space Y = Z<sub>p</sub>And K is the multiplication group Z<sup>*</sup><sub>p</sub>Is a set of all generators of. For any generator g K, the cryptographic function is the exponential function E<sub>g</sub>(x) = g<sup>x</sup>Defined as (mod p), the decoding function is the logarithmic function D<sub>g</sub>(y) = log<sub>g</sub>Defined as y (mod (p-1)).
Semi-stochastic ElGamal encryption (EG) extends exponential encryption to ElGamal encryption and executes ElGamal encryption in quasi-stochastic mode. X Z for each message<sub>p</sub>(Z for a prime number p<sub>p</sub>= {1, ... p-1}), where g is the multiplication group Z<sup>*</sup><sub>p</sub>The secret decryption key for the user is the random number a Z<sup>*</sup><sub>p-1</sub>And the public encryption key is α = g<sup>a</sup>(mod p) Zp, and the encryption Eα (x, r) is uniformly selected Random number r Z<sup>*</sup><sub>p-1</sub>Depends on. That is, Eα (x, r) = (g<sup>r</sup>(mod p), xα<sup>r</sup>(mod p)) = (s, t). For the encrypted message (s, t), the decryption function is Dα (s, t) = t (sα)<sup>-1</sup>(mod p).
<maths num="9"><img id="000010" he="57" wi="158" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>
Okamoto-Uchiyama Cryptography (OU) Okamoto and Uchiyama are additive public key cryptography in T. Okamoto and S. Uchiyama's "A New Public-Key Cryptosystemas Secure as Factoring" (Eurocrypt '98, Lecture Notes in Computer Science 1403, 308-318, 1998). Advocated the conversion method. This method is probabilistic and probably n = p against passive attackers<sup>2</sup>It would be as safe as the difficult factoring of q. Select two large prime numbers p and q out of k bits where k> 0, and n = p<sup>2</sup>Let q. g<sub>p</sub>= g<sup>p-1</sup>(mod p<sup>2</sup>) G Z so that the order is p<sup>*</sup><sub>n</sub>Is randomly selected. h = g<sup>n</sup>Let it be (mod n). The OU-style message space X is a set {1, ... 2 as claimed by Okamoto and Uchiyama.<sup>k-1</sup>Set Z (not})<sup>*</sup><sub>p</sub>And the cryptographic text space Y is Z<sub>n</sub>Is. For the user, the public key is a pair (n, g, h, k) and the corresponding private key is a pair of prime numbers (p, q). To encrypt the message x X, the random number r Z<sub>n</sub>Is uniformly selected. Then the encrypted message is y = E<sub>(n, g, h, k)</sub>(x, r) = g<sup>x</sup>h<sup>r</sup>(mod n). To decrypt the encrypted message y, the "logarithmic" function L: Γ Γ, L (x) = (x-1) p<sup>-1</sup>(mod p<sup>2</sup>) Is used. In the formula, Γ is Z<sup>*</sup><sub>p2</sub>Is a p-Sylow semigroup of, i.e. Γ = {x Z<sup>*</sup><sub>p2</sub>| x 1 (mod p)}. When the function L is used, the decoding function is x = D<sub>p, q</sub>(y) = L (y)<sup>p-1</sup>(mod p<sup>2</sup>)) L (g<sub>p</sub>)<sup>-1</sup>(mod p<sup>2</sup>).
A new additive encryption method can be constructed from an existing one by synthetic construction of the encryption method. In addition, synthetic construction can also be used when constructing an additive encryption method from a non-additive encryption method. For example, the combination of exponential cryptography Exp and arbitrary multiplication cryptography S (RSA, etc.) results in an additive cryptography.
As mentioned above, additive cryptography enables blind transformations with partially encrypted data that serve as the basis for a highly reliable interpretation of a document. In particular, additive cryptography can be used to blindly transform affine functions using plaintext coefficients and cryptographic variables.
Returning to the token-based document example, the token-based document D is the token image dictionary T and the position table L.<sub>i</sub>Since it consists of a sequence (one for each page image), the dictionary T and the position table L<sub>i</sub>Encrypted content of, encrypted token image dictionary T', and encrypted position table L'<sub>i</sub>Is intended to generate. Recall that the dictionary T consists of a collection of pairs (id [j], t [j]) (j = 1, ... | T |). Associated with T is an interpretation subroutine Lookup that returns the corresponding token image t in T given a valid token identifier id. When encrypting dictionary T, there are three basic options: token identifier encryption, token image encryption, or both. By encrypting the identifier or token image, it helps to unlink the connection between the identifier and its token image. In addition, the token image with ownership is protected by encrypting the token image. In any case, it is desirable to allow valid access to the dictionary only by the interpretation process P, while making it computationally difficult to obtain a copy of the entire plaintext content of the dictionary. This is possible. Because, in many cases, valid identifiers (eg Huffman codewords) are just a very small subset of all binary strings of a particular length, and as a result, no 100% search for identifiers is efficient. Because.
More formally, given a dictionary T and a Lookup subroutine to access it, the dictionary encryption requirement is that the encrypted dictionary T'and the corresponding subroutine Lookup' meet the following constraints: is there. (1) Arbitrary encryption identifier E<sub>k</sub>Lookup'(T', E) for (id)<sub>k</sub>(id)) = E<sub>k</sub>(Lookup (T, id)) (2) Reconstruction of T is computationally impossible even if T'and Lookup' are given.
For the encryption method S, T'and Lookup'can be constructed as follows. An ID is a set of all syntactically possible identifiers, especially an ID.<sup>*</sup> ID (ID in the formula<sup>*</sup>= {id | (id, t) T}). Let h be a one-way hash function whose domain is an ID. Next, for each pair (id, t) in T, a pair (h (id), E<sub>k</sub>Extract the encrypted token dictionary T'from T by inserting (t)) into T'. The converted subroutine Lookup'uses the following algorithm.<maths num="10"><img id="000011" he="97" wi="158" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>Note that the Lookup'return value is an encrypted token image. Decoding of this image will be described later. It is extended to the final subroutine Draw'of the interpretation process, which is part of the highly reliable interpretation.
The encryption of this dictionary can perform calculations using the encrypted version of the token dictionary in terms of both storage space overhead and runtime overhead. If the hash and encryption algorithms used in the Lookup'subroutine are sufficiently secure, recovery of T is computationally very difficult given T'and Lookup'.
Position table L<sub>i</sub>Each entry in is an identifier, as well as a position difference in the x and y coordinates, so any combination of these three elements can be encrypted. To encrypt location information, an additive encryption method is recommended so that any affine-type interpretation transformation can be applied to the position coordinates. With regard to identifiers, a trade-off between document compression and document protection must be made. In token-based documents, a token identifier is usually a codeword of some encoding intended for compression. For example, when a Huffman code is used to compress a document, the identifier is a binary Huffman codeword for the token, based on the number of occurrences in the document. In this case, simply using a deterministic encryption method to encrypt these identifiers does not effectively protect the identifiers. This is because this method does not change the number of occurrences of each token, so that anyone can recount the number of occurrences of the encryption identifier and reconstruct the Huffman codeword which is the identifier. Therefore, in order to hide the number of tokens generated in the document, it is preferable to encrypt the identifier by using a probabilistic encryption method. However, this encryption hinders the optimum encoding held in the identifier (codeword) and reduces the compression ratio of the document. This may not be desirable for token-based documents, as achieving good document compression is one of the design goals for token-based documents.
L<sub>i</sub>Propose a reasonable compromise to encrypt. If the efficiency of encryption and decryption is not a major issue, choose an additive encryption method S, preferably a probabilistic and asymmetric one such as the Okamoto-Uchiyama cryptographic OU. L<sub>i</sub>For each entry (id, x, y) in<sub>k</sub>(x), E<sub>k</sub>(y)) to L'<sub>i</sub>Insert in. If identifier encryption is also required, then (E<sub>k</sub>(id), E<sub>k</sub>(x), E<sub>k</sub>Make an entry like (y)) in the position table L'<sub>i</sub>Can be inserted into. However, in this case, the entry to the encryption dictionary T'is (E).<sub>k</sub>(id), E<sub>k</sub>It needs to be changed to (t)), and the above-mentioned subroutine Lookup'needs to be modified to reflect this change.
The token-based document format preservation encryption described above can also be used to protect the content of the document during the interpretation process. Intended to delay encryption to Draw'(x, y, t). The interpretation process is as shown below.
<maths num="11"><img id="000012" he="218" wi="98" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></maths>In this process, all the coordinate and token image information remains encrypted before calling the subroutine Draw'(x, y, t). This is possible for coordinate information because this encryption method is additive. As a result, the content protection level of the interpretation process and the performance of the interpretation process depend on the confidentiality strength of the method used and the complexity of the calculation.
In another embodiment of the present invention, the electronic work is made secret so that the electronic work can be interpreted or reproduced with high reliability without releasing the secret story of the electronic content or presentation data. In this embodiment, the electronic work is of a type that includes electronic content and resource information (also referred to as system context). Resource information includes formal information or other information used by a reproduction or interpretation application to convert an electronic work into presentation data.
Confidentialization is a type of conversion process that makes the original content unreadable or unusable. For the electronic work w, the secret story method T using the seed s generates the secret story electronic work w'according to w'= T (w, s). Using the same transformation T, the confidential resource information S'can also be generated according to S'= T (S, s). In this example, seeds are used to make reverse engineering of the secret story method more difficult.
For example (For example), a document-type electronic work can be esoteric using a concise esoteric scheme. In a document, electronic content contains a series of characters in a particular order or in a particular position. When displaying this document on a display device, each character must be displayed in a specific position so that the user can view it on a display device such as a monitor. A coordinate system is required to display each character on the monitor, which allows each character in the document to be displayed on the monitor. The electronic content contains coordinate information, which is referenced by the monitor's coordinate system. For example, in this paragraph, the letter "F" appears on the top line, five characters below the beginning of the line.
A concise secretive method for jumping the text in the upper paragraph is to move the position of the characters relative to the coordinate system. Each character in the paragraph has a position of (x, y). It is assumed that the position (x, y) of each character in the above paragraph is made secret by using the seed (a, b) from the user system. The above paragraph can be made secret by using the secretary function below. About the vertical axis Y = b<sup>y</sup> About the horizontal axis X = x / a
In this example, in order for the playback application to convert the electronic content into presentation data, that is, to display the paragraphs on the monitor without scrambling, the coordinate system of the user's device must be kept secret. To generate the Confidential Coordinate System, the coordinate system of the user's device must be Confidential using the same seed (a, b). The conversion function below is used to calculate the positions of both x and y at a given point. About the vertical axis Y = log<sub>b</sub>(Y) (log<sub>b</sub>Is the logarithm with the base b) About the horizontal axis X = aX
When a playback application obtains the position of a character in a secreted electronic work, this position is (X, Y) = (x / a, b).<sup>y</sup>). Then apply this value to the coordinate system of the device and (X, Y) = (log<sub>b</sub>Let (Y), aX) = (x, y). The exact location of the "F" is thus displayed on the user's monitor. In the case of both secret stories, the resource information and the secret story form of the electronic work maintain a unique link. These complementary confidential forms of resource information and electronic works lay the foundation for an effective mechanism for protecting electronic works. While the playback application can display the secret story electronic work, the playback application can provide plaintext presentation data only using the context of the secret story system.
In general, secrecy is not as strict as encryption, but different levels of secrecy can be used depending on the importance of the electronic work being protected. Higher importance works may require a higher level of confidentiality, and less important works may require a weaker type of confidentiality. If the user's environment is highly reliable, a low level of confidentiality can be used. The advantage of using low-level esoteric work is that it requires less system resources to create the esoteric electronic work and to interpret or reproduce the esoteric electronic work. It is also possible to use the type and quality of the esoteric seed in combination with the esoteric method to determine the level and intensity of the esoteric. For example, more complex securitization seeds (such as those containing authorization information from highly reliable sources, or dynamic seeds) will result in higher levels of secrecy and intensity.
Confidentialization generally occurs at the distribution or manufacturing site. The electronic work is usually esoteric using a confidentialization method chosen by the manufacturer or distributor before it is distributed to the user or customer. Resource information to be kept secret can also be selected in advance before delivery. It is preferable to use a seed for each secret talk method. It is also preferable to generate seeds using the information provided by the context of the user system.
When a user purchases an electronic work, the user preferably provides information from a user system designated for reproduction of the electronic work. This information can be used to generate a secreted seed for both the secreted electronic work and the secreted resource information (sometimes referred to as the secreted system context). Then, the secret story electronic work and the secret story system context or the secret story resource information are provided to the user. Further, although not required by the operation of this embodiment of the present invention, in general, the secret story electronic work and the secret story system context can be encrypted before distribution to the user. Depending on the decoding method used, it may be necessary to decode both the secret story electronic work and the secret story system context before reproducing the secret story electronic work into the presentation data.
The method of generating a secret story electronic work can be divided into three steps. These steps are the generation of esoteric seeds, the esotericization of electronic works, and the esotericization of resource information. When the secret story seed is generated, the secret story engine is given the secret story seed. The secretive engine uses electronic work or resource information as input and generates a secretive form of electronic work or resource information based on a conversion function given a secretive seed. When reproducing a secret story electronic work, presentation data and / or image data is generated using the secret story resource information. The same or different confidential conversion functions can be used for electronic works and resource information.
The method of generating a secret story electronic work is shown in connection with FIG. Electronic work 1410 includes electronic content and a set of resource information used to format and interpret the electronic content in a format that can be used or displayed by the user. The electronic work 1410 is processed by the content secretive 1420, and in this process, the electronic content is made secret, resource information is stored, and the secret electronic work 1422 is generated. Content secrecy 1420 can occur as shown in connection with Figure 9. Electronic works generally include content, instructions, and formats. Although the entire electronic work can be kept secret, it is preferable that only the content is kept secret and the instructions and formats are not kept secret. However, in some cases, some of the resource information contained in the electronic work can also be kept secret for some playback applications. This also applies to the above-mentioned format storage encryption method.
Resource extraction 1412 extracts at least one resource information from a set of resource information related to electronic work 1410. Extraction is done by copying the resource information to the system resource file 1414. Then, in resource concealment 1416, the system resource 1414 is concealed and made into concealed system resource 1424. It is not necessary to use the same secret talk method for content secret talk and resource secret talk. For each secrecy method, it is preferable to use the secrecy seed 1418 generated by the seed generator 1426. Some exemplary seed generation methods will be described below. In particular, in a preferred embodiment, the confidential seed is based on unique information from the user system.
Several techniques for generating confidential seeds can be used. For example, a seed generator that generates numbers from a random number generator can be used. This method, called stateless secrecy, does not rely on either private key information or user system information. The stateless secrecy method produces specific values for the secrecy system. Weaknesses inherent in electronic security systems can be found in mishandling confidential information, mathematical complexity, and algorithmic complexity. Removing confidential information reduces the target of the attack by one. Due to stateless secret talk, the random number generator generates a secret talk seed. In this case, when the confidentialization process is completed, the seed is discarded without leaving a trace. Therefore, the security of the system avoids attacks concentrated on the leakage of confidential information, and the user does not have to leak important information that may be a violation of privacy.
Another seed generator that can be used is a state-based generator. The state-based seed generator first builds a seed by obtaining information about the state of the system from the user's playback system or interpreter. System status information includes hardware identifiers, system settings, and other system-related information. Although stateless confidentiality is highly rated, other safety requirements may require the use of indivisible links to specific user systems or devices. By generating a secreted seed from information specific to the system / device, the secreted engine produces a secreted electronic work in a format that corresponds to a particular system / device.
Confidential seed generators can also be associated with authorization processing. Permit-based secrecy allows seed generation to be associated with the outcome of the permit process. A separate authorization repository (which is a reliable source) provides authorization information as part of other security features related to delivering access to electronic works to users. A reliable source of authorization information can be an online authorization repository, such as that described in US Pat. No. 5,629,980. Then, this permission information is used to generate a confidential seed.
When using a stateless secret story seed, the electronic work and its resource information can be secreted, stored together, and sent to the user when the user purchases the usage right related to the specific electronic work. If you use one of these other methods of generating confidential material, you generally have to wait for the user to provide system information or authorization information, after which the electronic work and the electronic work and Resource information can be kept secret.
Embodiments that provide a higher level of protection in ensuring that an electronic work is playable on a particular physical system or device use dynamic state-based confidential seeds. In this embodiment, the secrecy engine and the secrecy seed generator, along with information on the electronic work and resources, must be provided to the playback application or interpreter. In this embodiment, prior to reproduction and interpretation, information on electronic works and resources is secreted using seeds generated based on the dynamic state of a particular system or device. Dynamic states can arise from, for example, system clocks, CPU utilization, hard drive placement, cursor coordinates, and so on. By concealing a work with snapshots of dynamic states, the work is tuned to lock into a particular system configuration (ie, state). The secrecy of electronic works, and ultimately their blind reproduction (discussed below), is based on dynamic evolution. Since the evolution of the dynamic state does not generate unique confidential information that enables the reproduction of the secret story processing, the secret story based on the dynamic state makes it difficult to leak the secret story electronic work and the system context. This means that it is impossible to unravel the construction of this process, as the confidentialization process takes place within a highly reliable system.
As explained in the previous example, the actual processing of concealment can be parameterized by algorithm-based transformation with the concealment seed. When making a secret story, the data and resource identifier of the electronic work are converted as described above. However, the structure of the electronic work does not change, and the original format, such as PDF, DOC, WAV, or other format, is preserved as it was with format-preserving encryption. Similarly, the secrecy of resource information creates a secret form of resource information, which transforms resource identifiers, element identifiers and resource characteristics, but leaves the structure of the system context unchanged. Based on the user's specific device or system information, the inseparable relationship is established by confidentializing the information of the electronic work and the resource with the same seed, and the work can be used with any other device or user system. It cannot be played back in its plaintext format. Protection remains in effect, even if distributed without permission.
During blind playback, the unique properties of the secreted resource information allow the playback application to properly reproduce the secreted electronic work and generate non-secreted, or plaintext, presentation data. Since the electronic work and the resource information are complementarily converted, the secretive element of the electronic work such as the resource identifier and the data refers to the complementary element in the resource of the system context without knowing the contents. The collation transformation identifies the appropriate element in the context by the playback application, and the resulting presentation data appears in clear text. Therefore, the copyrighted work is protected as much as possible after reproduction.
As mentioned above, traditional distribution of electronic works over the web is relatively easy. A work is created using an editor, posted on a website, accessed by a user reader, and played on a display device or system. If the content owner does not want to protect his or her electronic work (or if the content owner trusts all users who receive the work), then the electronic work is "plaintext", ie encoded, encrypted or otherwise. It is provided in a form that can be used directly by any user without any protection.
When an electronic work is downloaded to a user system, the electronic work is generally stored in memory. When an electronic work is provided via a storage medium such as a floppy (registered trademark) disc, CD-ROM or DVD-ROM, the electronic work is usually accessed directly from the storage medium.
Referring to FIG. 15, the electronic work 1510 is provided to the reproduction application 1512 in order to reproduce the electronic work. In the case of a document or other type of work that requires formal or resource information, the electronic work contains the electronic content and the specific system context or system resources required for the playback application to process the electronic content. Includes the resource information to be shown. For example, electronic work 1510 can be a text document in which the text is displayed using the Arial font. When the playback application 1512 accesses the resource information of the electronic work 1510 indicating that it uses the Arial font, the playback application 1512 accesses the appropriate system resource 1516 (in this case, the Arial font table) and the system. Convert electronic content to presentation data 1514 using resource information.
In some playback applications, the conversion of electronic content to presentation data is sufficient for the user to use. In other playback applications, the presentation data is only in intermediate format and requires further conversion. For example, in the case of the display system 1524, which is a printer, the presentation data 1514 must be further interpreted by the interpretation application 1518. The interpretation application 1518 can be an analyzer in the printer. The interpretation application 1518 uses other system resources 1516 to convert the presentation data 1514 into image data 1520. The format of the image data 1520 can be displayed directly on the display device 1522 (in the case of a printer, it is output as a printed document).
In addition to the systems and methods described above that protect the electronic work during playback, by making the electronic work secret according to the first secreting method of generating confidential content and storing the resource information of the electronic work. Electronic works can be protected during playback. Copy a part of the resource information of the electronic work and make it a secret story according to the second secret story method. Referring to FIG. 16, the reproduction application 1612 uses the confidential resource information 1614 (and any other system resource information 1616 that may be needed) to convert the confidential electronic work 1610 into plain presentation data 1618. The presentation data is necessarily in clear text format, which means that the presentation data is available to other programs (such as screen capture utility programs). However, the output of such other programs is often not in the same format and fidelity as the original electronic work.
The secret story resource information can be considered to act like a secret story filter that turns the secret story electronic content into a plaintext image (presentation data). This system is a blind playback system in that a playback application, which can be any commercial application, does not know or need to know plaintext electronic content. Blind regeneration acts on any transformation function R, and R (w', s') = R (w, s). In the formula, w'is the secret story electronic content, w is the plaintext electronic content, s'is the secret story resource information, and s is the non-secret story resource information. Blind reproduction of a secret story electronic work using secret story resource information differs from the above-mentioned blind conversion in that blind playback generates plaintext presentation data without the need to release the secret story. There is. In blind conversion, the playback application must convert the encrypted electronic work into encrypted presentation data and then decrypt it. In both cases, the user does not view the original electronic work in clear text.
Only blind reproduction (also called blind interpretation) using confidential electronic works and confidential resource information can be used to protect electronic works during reproduction in addition to normal encryption. For example, the secret story electronic work and the secret story resource information can be encrypted to protect the electronic work at the time of distribution, and then the user system can decrypt these into the secret story electronic work and the secret story resource information. The user must first obtain permission from the content owner or the distributor who works on behalf of the content owner (to decrypt the encrypted electronic work). When the user is authorized, the encrypted secret story electronic work and the encrypted secret story resource information are decrypted, and the secret story electronic work is played back by the playback application using the secret story resource information.
The complexity of interpreting an electronic work in a format available for display by the user can be used to further protect the electronic work during reproduction. Referring to FIG. 17, the secret story electronic work 1710 is provided to the playback application 1712, which uses the secret story system resource 1716 and other system resources 1718 to partially use the secret story electronic work 1710. Convert to the secret story data 1714. In this embodiment, a display system 1728 is required to convert the presentation data into a format that can be used by the user. Partially Confidential Presentation Data 1714 was provided to Interpretation Application 1720, which was partially Confidential Using Confidential System Resource 1716, Local System Resource 1722, and System Resource 1718. Convert presentation data 1714 to plain image data 1724. Next, the plaintext image data 1724 is displayed on the display device 1726 for use by the user. In this embodiment, the presentation data is still kept secret, obscuring the location of the plaintext data until a later point in the display process, providing additional protection.
In order to enhance the usefulness of the system for making the electronic work secret, the confidential resource information may be separated from the electronic work and associated with a portable device such as a smart card. In this embodiment, the playback application 1712 uses the secret story system resource 1716 to play the copyrighted work. Instead of storing the Confidential System Resource 1716 in local memory, store the Confidential System Resource 1716 along with the Confidential Electronic Work 1710 in a portable device such as a smart card. In addition, smart cards that may have hardware enhancements can have attributes that make them difficult to change. Within the portable context, the confidential data is processed by the playback application 1712 to produce partially confidential presentation data, which is then provided to the interpretation application 1720.
Many different types of electronic works can be protected using confidentiality schemes throughout their use. For example, if the electronic work is a document or text file, the playback application can be a word processor, and system resources or resource information can include font tables, page layouts, and color tables. If the electronic work is audio or video data (eg, a stream), the playback application can be an audio or video player. Presentation data is a stream of final audio / video data. The display system can be an audio / video device. The interpretation application can be a driver for audio / video equipment. The image data can be a data stream of an audio / video device, and the display device can be an interpreter (for example, a speaker or a monitor) of the audio / video device.
For electronic works that are audio / video data streams, system resources or resource information are the characteristics of the audio / video device: sampling rate (sampling per second, eg 8kHz, 44.1kHz), sampling quality (sampling). The number of bits per bit, eg 8, 16), sampling type (number of channels, eg monaural 1, stereo 2), and sampling format (blocks of instructions and data) can be included. Below is a table of several audio / video data streams and corresponding resource information or variable parameters that can be selected for confidentiality.
<tables num="1"><img id="000013" he="97" wi="158" file="JP5331920B2_D0001.tif" img-format="tif" img-content="drawing" /></tables>
The structure of an electronic work can be significantly used for confidentiality. Although the entire electronic work can be kept secret, it is more preferable to keep only a part of the electronic work secret. Most electronic works contain three main elements: instructions, data, and resources. Similar to the format preservation encryption method described above, it is preferable to keep only the data and resources of the electronic copyrighted work confidential. By selectively converting only the data and resources, the electronic work can be converted so that the content remains in its original format but the data and resources are incomprehensible.
Figure 18 shows the general layout of a document-type electronic work. In FIG. 18, electronic work 150 includes a page descriptor 152, control codes 154, 158 and 162, a resource identifier 156, and data 160 and 164. Page descriptor 152 defines the general layout of a work. For example, page size, number of pages, and margins fall within the scope of page descriptors for electronic documents. Control codes 154, 158 and 162 are similar in that they describe a presentation of content. Examples include text position setting commands, text output commands, font type setting commands, and current screen coordinate setting commands. Resource identifier 156 simply refers to the desired resource. In the field of electronic documents, resources range from typefaces to background colors. Finally, data 160 and 164 represent the core of information transmitted by electronic works. This can be the drawing coordinates used for the multimedia clip, or the character code for interpretation as an electronic document.
An example of an electronic work (in this case a concise electronic document) and its secretive form is shown in FIGS. 19 and 20 as an HTML document in plaintext and secretive form. The <html> and <body> tags are page descriptors. The tags from <font> to <\ font> are examples of control codes that set font resource characteristics, and "Arial" and "14" are resource identifiers for 14-point fonts in Arial typeface. The text of "Hello World" is the core of the information of the data, the copyrighted work. <p> is another control code that marks the beginning of a paragraph. Finally, the document ends with page descriptors <\ body> and <\ html> to identify the end of the document.
FIG. 20 shows what the electronic work of FIG. 19 looks like in a secret story format. It can be seen that the page descriptor and control code tags remain unchanged, i.e. the <html>, <body> and <font> tags remain unchanged. On the other hand, the resource identifiers "Arial" and "14" are converted to undecryptable values. Similarly, the data "Hello World" has also been converted to an undecryptable value. By converting the resource identifier and the data, the content is in a secret form and becomes meaningless. However, due to the fact that the page descriptor and control code remain unchanged, the document can retain its original format, which is generally HTML, Adobe PDF, RealNetworks RAM, Apple's. QuickTime etc. are possible.
A system context (or system resource or resource information) can be thought of as a collection of system resources available for a playback application on a particular system. For example, the system context may include a font table, a color palette, system coordinates and volume settings. When an electronic work is input to a playback application, the playback application converts the electronic content into presentation data using specific resource information contained in the electronic work. Each system context or resource information contained within an electronic work can be modified to be unique to the system and playable for that system. The system context is an essential element of the use of an electronic work and, for reproduction, associates the use of the electronic work with a particular system, physical device or application for reproduction. Resource identifiers and data in electronic works can directly or indirectly refer to elements contained within the system context. Confidentialization of electronic works and system contexts allows for blind interpretation of plaintext presentation data. By escorting a system context with an esoteric seed associated with a unique system, the resulting esoteric system context can be a unique environment, within which the same esoteric seed can be used as an esoteric story. You can access and replay the complementary, esoteric electronic works that have been converted.
FIG. 21 shows the general structure of the system context. These elements include a resource identifier (ResID), an element identifier (ElemID), and a resource characteristic (Characteristics). The ResID contains relevant information for other system components to reference the resource. ElemID is an identifier for each element in the resource. Finally, Characteristics are the actual resource characteristics used to represent individual resource elements.
FIG. 22 is a diagram of font table resources for Arial typeface. The main resource identifier in this case is the font name "Arial". Following ASCII rules, number 48 identifies individual resource element identifiers. The resource element characteristic of ElemID represents the information to represent the letter'a'.
FIG. 23 is a diagram of the secret story system context of the font resource shown in FIG. The resource identifier itself has been converted to "k13k2". The element identifier itself is sufficient to convert only the resource characteristics and does not need to be converted. In this case, "48" is shown as transformed to represent the property of'Y'instead of'a'.
Confidentialization and blind interpretation can be used for many different types of electronic works. Confidentialization and blind interpretation can be used for audio / video data as well as documents. As mentioned above, audio / video data is generally provided in the form of streams. The playback application is an audio / video player that converts a digital audio / video stream into a final data stream, which can be processed into audio output by a converter (speaker) or into a video image by display. can do.
Referring to FIG. 17, the playback application 1712 corresponds to an audio / video player, which generally extracts the audio / video input stream 1710 at a sampling rate, quality and type allowed by the audio / video device of interest. It works by doing. The audio / video player uses audio / video system resources to extract, mix and generate audio / video streams, then mix the re-extracted audio / video streams to achieve the final audio / video stream. Generates in the desired format. For audio / video players, presentation data 1714 is the final mixed audio / video stream that is the sampling rate, quality, type, and format desired by the audio / video device of interest.
An audio / video device of interest (eg, interpretation application 1720) sets an audio / video stream (presentation data 1714) at a particular sampling rate, quality, type (channel), and format (eg, PAL or NTSC). It is a hardware system that can convert the audio / video data of 1724. Examples of audio equipment include sound cards, speakers, monitors, and digital-to-analog converters located within audio / video equipment. Many devices are capable of playing audio / video streams in a range of different sampling rates. Image data 1724 (eg, a stream of audio signals or video images) is generated by the audio / video device driver 1720 and "consumed" by the display device 1726.
For example, to keep an audio / video data stream secret, this stream can be split into two or more separate streams. One stream is a secret story, the other stream is not a secret story. Each stream can have various device characteristics (resource information) such as associated sampling rate, channel, quality and format. Device characteristics (one or more of stream sampling rate, channel, quality and / or format) can also be concealed to generate concealed resource information.
Blind playback of a secret audio / video stream is achieved in the same way as a secret electronic document. The playback application (audio / video player) mixes both the unsecreted stream and the secreted stream and uses the secreted resource information to have the correct set of resource information for the desired audio / video device. Generate a secreted final data stream. The target device (1720) reproduces the confidential data stream using the confidential resource information to generate a plaintext audio / visual effect (1724).
Some of the exemplary embodiments of the invention have been described in detail above, but other forms, alternatives, modifications, and variants of the invention will work as well, which will be apparent to those skilled in the art. Should be recognized. This disclosure is not intended to limit the invention to any particular embodiment, but is intended to include all such forms, alternatives, modifications, and variants. For example, some of the aforementioned inventions described as software components can be implemented as hardware. Further, although some functional blocks have been described herein as separate and independent of each other, these functional blocks can be integrated and run on a single general purpose computer, or the art. As recognized in, it can be further divided into sub-functions. Therefore, the true scope of the invention is intended to include all alternatives, modifications and equivalents, and this scope should be determined with reference to the claims described below.
1010, 1410, 1710 Electronic works 1012, 1612, 1712 playback application 1016 Encrypted presentation data 1018 Decryption engine 1020 presentation data 1022, 1720 Interpretation application 1024, 1724 Image data 1026, 1726 Display 1412 Resource extraction 1414, 1616, 1718 System resources 1416 Resource secrecy 1418 Confidential Seed 1420 Content Confidential 1422, 1610 Confidential Electronic Works 1424, 1614, 1716 Confidential System Resources 1426 Seed generator 1618 Plaintext presentation data 1714 Partially confidential presentation data 1722 Local system resources 1728 Display system
Every citation, both waysCites: the store holds 6 of 7
| Document | Relation | Office |
|---|---|---|
| JP10055135A | Cites | Japan |
| JP10091376A | Cites | Japan |
| JP10327211A | Cites | Japan |
| JP11008842A | Cites | Japan |
| JP2000010929A | Cites | Japan |
| JP2000163408A | Cites | Japan |
36 members in 7 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 534756 | United States of America | – | |
| 53475600 | United States of America | A | |
| 53475600 | United States of America | A | |
| 2000534756 | – | – | – |
| US20000534756 | – | – | – |
Members36
| Document | Office | Kind | |
|---|---|---|---|
| EP0999488A2 | European Patent Office (EPO) | A2 | |
| JP2000137649A | Japan | A | |
| CA2341979A1 | Canada | A1 | |
| EP1146411A1 | European Patent Office (EPO) | A1 | |
| JP2002044072A | Japan | A | |
| EP0999488A3 | European Patent Office (EPO) | A3 | |
| US2002194485A1 | United States of America | A1 | |
| US6519700B1 | United States of America | B1 | |
| US6763464B2 | United States of America | B2 | |
| EP0999488B1 | European Patent Office (EPO) | B1 | |
| AT303630T | Austria | T | |
| ATE303630T1 | Austria | T1 | |
| DE69926970D1 | Germany | D1 | |
| EP1146411B1 | European Patent Office (EPO) | B1 | |
| AT307353T | Austria | T | |
| ATE307353T1 | Austria | T1 | |
| DE60114069D1 | Germany | D1 | |
| EP1612641A2 | European Patent Office (EPO) | A2 | |
| EP1612641A3 | European Patent Office (EPO) | A3 | |
| DE69926970T2 | Germany | T2 | |
| ES2248952T3 | Spain | T3 | |
| ES2250245T3 | Spain | T3 | |
| DE69926970T8 | Germany | T8 | |
| DE60114069T2 | Germany | T2 | |
| US7068787B1 | United States of America | B1 | |
| JP2007328798A | Japan | A | |
| JP4235691B2 | Japan | B2 | |
| JP4304220B2 | Japan | B2 | |
| JP2009201163A | Japan | A | |
| JP4353651B2 | Japan | B2 | |
| JP2012168561A | Japan | A | |
| JP2013214993A | Japan | A | |
| JP5331920B2This record | Japan | B2 | |
| EP1146411B2 | European Patent Office (EPO) | B2 | |
| DE60114069T3 | Germany | T3 | |
| ES2250245T5 | Spain | T5 |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 |
Numbers
- Publication
- 5331920
- Publication, DOCDB
- 5331920
- Publication, EPODOC
- JP5331920B
- Application
- 120503
- Application, DOCDB
- 2012120503
- Application, EPODOC
- JP20120120503
Titles2
- Japanese
- コンピュータ可読記憶媒体
- English
- Computer-readable storage medium
Classification
- CPC, 1
- G06F21/10
- IPC, 8
- G09C1 00
- G06F21 62
- G06F12 14
- G06F1 00
- G06F21 10
- G06Q50 00
- H04L9 08
- H04L9 16