Information processing unit and method, information processing system and serving medium
Abstract
Problem to be solved.To prevent illegal copying of data by using an illegal device.
Solution.A management center 110 generates a revocation list that describes a device- ID of a device in which information to be kept secret is exposed and sends the generated revocation list to a data broadcast receiver 130 via, e.g. a satellite 120. When the revocation list has been received from the management center 110, the data broadcast receiver 130 compares the device- ID indicated in a received revocation list with a device- ID described in the revocation list in a CDT(connected device- ID table). In the case a device- ID being coincident with the device- ID described in the revocation list in the CDT is detected, the device connected via a 1394 bus 11 is informed of the device- ID.

Term
Term ended
Projected expiry passed 12 January 2018, 8.7 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
17 claims: 10 independent, 7 dependent
- 1[Claims] [Claim 1] A means for creating a list in which the identification number of the first information processing device in which information to be kept secretly is exposed among other information processing devices is described, and Information processing characterized in that the list created by the creation means is provided with a providing means for providing the list to a second information processing device other than the first information processing device among the other information processing devices. apparatus. 【特許請求の範囲】 【請求項1】 他の情報処理装置のうち、秘密裡に保管しておくべき情報が露呈された第1の情報処理装置の識別番号が記されたリストを作成する作成手段と、 前記作成手段により作成された前記リストを、前記他の情報処理装置のうち、前記第1の情報処理装置以外の第2の情報処理装置に提供する提供手段とを備えることを特徴とする情報処理装置。
- 4Among other information processing devices, a creation step of creating a list in which the identification number of the first information processing device in which information to be kept secretly is exposed is described, and Information processing characterized in that the list created in the creation step is provided to a second information processing device other than the first information processing device among the other information processing devices. Method. 【請求項4】 他の情報処理装置のうち、秘密裡に保管しておくべき情報が露呈された第1の情報処理装置の識別番号が記されたリストを作成する作成ステップと、 前記作成ステップで作成された前記リストを、前記他の情報処理装置のうち、前記第1の情報処理装置以外の第2の情報処理装置に提供する提供ステップとを備えることを特徴とする情報処理方法。
- 5Among other information processing devices, a creation step of creating a list in which the identification number of the first information processing device in which information to be kept secretly is exposed is described, and To provide a computer program having a providing step of providing the list created in the creation step to a second information processing device other than the first information processing device among the other information processing devices. Characterized delivery medium. 【請求項5】 他の情報処理装置のうち、秘密裡に保管しておくべき情報が露呈された第1の情報処理装置の識別番号が記されたリストを作成する作成ステップと、 前記作成ステップで作成された前記リストを、前記他の情報処理装置のうち、前記第1の情報処理装置以外の第2の情報処理装置に提供する提供ステップとを有するコンピュータプログラムを提供することを特徴とする提供媒体。
- 6In an information processing device that transmits encrypted data to another information processing device connected via a predetermined transmission line. A storage means for storing the identification numbers of the other information processing devices as an identification number table, and A receiving means for receiving a list of information processing device identification numbers that reveal information that should be kept secretly, and A comparison means for comparing the identification number in the list received by the receiving means with the identification number in the identification number table stored by the storage means. An information processing device including a transmission means for transmitting the encrypted data to the other information processing device in response to a comparison result by the comparison means. 【請求項6】 所定の伝送路を介して接続されている他の情報処理装置に暗号化データを伝送する情報処理装置において、 前記他の情報処理装置の識別番号を識別番号テーブルとして記憶する記憶手段と、 秘密裡に保管しておくべき情報が露呈された情報処理装置の識別番号が記されたリストを受信する受信手段と、 前記受信手段により受信された前記リストに記されている前記識別番号と、前記記憶手段により記憶された前記識別番号テーブル中の前記識別番号とを比較する比較手段と、 前記比較手段による比較結果に対応して、前記暗号化データを前記他の情報処理装置に伝送する伝送手段とを備えることを特徴とする情報処理装置。
- 11The transmission means further comprises transmitting the identification number table including the identification number to which the flag is added by the addition means to the other information processing apparatus. The information processing device described in. 【請求項11】 前記伝送手段は、さらに、前記付加手段により前記フラグが付加された前記識別番号を含む前記識別番号テーブルを、前記他の情報処理装置に伝送することを特徴とする請求項9に記載の情報処理装置。
- 13In an information processing method in an information processing device that transmits encrypted data to another information processing device connected via a predetermined transmission line. A storage step of storing the identification numbers of the other information processing devices as an identification number table, and A receive step that receives a list of information processing device identification numbers that reveal information that should be kept secretly, and a receive step. A comparison step of comparing the identification number in the list received in the reception step with the identification number in the identification number table stored in the storage step. An information processing method comprising a transmission step of transmitting the encrypted data to the other information processing apparatus in accordance with the comparison result in the comparison step. 【請求項13】 所定の伝送路を介して接続されている他の情報処理装置に暗号化データを伝送する情報処理装置における情報処理方法において、 前記他の情報処理装置の識別番号を識別番号テーブルとして記憶する記憶ステップと、 秘密裡に保管しておくべき情報が露呈された情報処理装置の識別番号が記されたリストを受信する受信ステップと、 前記受信ステップで受信された前記リストに記されている前記識別番号と、前記記憶ステップで記憶された前記識別番号テーブル中の前記識別番号とを比較する比較ステップと、 前記比較ステップにおける比較結果に対応して、前記暗号化データを前記他の情報処理装置に伝送する伝送ステップとを備えることを特徴とする情報処理方法。
- 14In a providing medium that provides a computer program used in an information processing device that transmits encrypted data to another information processing device connected via a predetermined transmission line. A storage step of storing the identification numbers of the other information processing devices as an identification number table, and A receive step that receives a list of device identification numbers that reveal information that should be kept secretly, and a receive step. A comparison step of comparing the identification number in the list received in the reception step with the identification number in the identification number table stored in the storage step. A providing medium comprising providing a computer program having a transmission step of transmitting the encrypted data to the other information processing apparatus in response to the comparison result in the comparison step. 【請求項14】 所定の伝送路を介して接続されている他の情報処理装置に暗号化データを伝送する情報処理装置に用いられるコンピュータプログラムを提供する提供媒体において、 前記他の情報処理装置の識別番号を識別番号テーブルとして記憶する記憶ステップと、 秘密裡に保管しておくべき情報が露呈された装置の識別番号が記されたリストを受信する受信ステップと、 前記受信ステップで受信された前記リストに記されている前記識別番号と、前記記憶ステップで記憶された前記識別番号テーブル中の前記識別番号とを比較する比較ステップと、 前記比較ステップにおける比較結果に対応して、前記暗号化データを前記他の情報処理装置に伝送する伝送ステップとを有するコンピュータプログラムを提供することを特徴とする提供媒体。
- 15In an information processing system including a first information processing device to a third information processing device, The first information processing device is A means of creating a list showing the identification numbers of the third information processing apparatus in which information to be kept secret is exposed, and a means for creating the information. A providing means for providing the list created by the creating means to the second information processing apparatus is provided. The second information processing device is A storage means for storing the identification numbers of the third information processing apparatus connected via a predetermined transmission line as an identification number table, and A receiving means for receiving the list provided by the providing means of the first information processing apparatus, and a receiving means for receiving the list. A comparison means for comparing the identification number shown in the list received by the receiving means with the identification number in the identification number table stored by the storage means. An information processing system including a transmission means for transmitting encrypted data to the third information processing device in response to a comparison result by the comparison means. 【請求項15】 第1の情報処理装置乃至第3の情報処理装置により構成される情報処理システムにおいて、 前記第1の情報処理装置は、 秘密裡にしておくべき情報が露呈された前記第3の情報処理装置の識別番号を示したリストを作成する作成手段と、 前記作成手段により作成された前記リストを前記第2の情報処理装置に提供する提供手段とを備え、 前記第2の情報処理装置は、 所定の伝送路を介して接続されている前記第3の情報処理装置の識別番号を識別番号テーブルとして記憶する記憶手段と、 前記第1の情報処理装置の前記提供手段により提供された前記リストを受信する受信手段と、 前記受信手段により受信された前記リストに示されている前記識別番号と、前記記憶手段により記憶された前記識別番号テーブル中の前記識別番号とを比較する比較手段と、 前記比較手段による比較結果に対応して、前記第3の情報処理装置に暗号化データを伝送する伝送手段とを備えることを特徴とする情報処理システム。
- 16In an information processing method in an information processing system including a first information processing device to a third information processing device. The first information processing device is A creation step to create a list showing the identification numbers of the third information processing device that reveals information that should be kept secret. It includes a providing step of providing the list created by the creating step to the second information processing apparatus. The second information processing device is A storage step of storing the identification number of the third information processing apparatus connected via a predetermined transmission line as an identification number table, and a storage step. A receiving step for receiving the list provided by the providing step of the first information processing apparatus, and a receiving step for receiving the list. A comparison step of comparing the identification number shown in the list received by the reception step with the identification number in the identification number table stored by the storage step. An information processing method comprising a transmission step of transmitting encrypted data to the third information processing apparatus in response to a comparison result of the comparison step. 【請求項16】 第1の情報処理装置乃至第3の情報処理装置により構成される情報処理システムにおける情報処理方法において、 前記第1の情報処理装置は、 秘密裡にしておくべき情報が露呈された前記第3の情報処理装置の識別番号を示したリストを作成する作成ステップと、 前記作成ステップにより作成された前記リストを前記第2の情報処理装置に提供する提供ステップとを備え、 前記第2の情報処理装置は、 所定の伝送路を介して接続されている前記第3の情報処理装置の識別番号を識別番号テーブルとして記憶する記憶ステップと、 前記第1の情報処理装置の前記提供ステップにより提供された前記リストを受信する受信ステップと、 前記受信ステップにより受信された前記リストに示されている前記識別番号と、前記記憶ステップにより記憶された前記識別番号テーブル中の前記識別番号とを比較する比較ステップと、 前記比較ステップによる比較結果に対応して、前記第3の情報処理装置に暗号化データを伝送する伝送ステップとを備えることを特徴とする情報処理方法。
- 17A providing medium for providing a computer program used in an information processing system composed of a first information processing device to a third information processing device. The first information processing device is A creation step to create a list showing the identification numbers of the third information processing device that reveals information that should be kept secret. It includes a providing step of providing the list created by the creating step to the second information processing apparatus. The second information processing device is A storage step of storing the identification number of the third information processing apparatus connected via a predetermined transmission line as an identification number table, and a storage step. A receiving step for receiving the list provided by the providing step of the first information processing apparatus, and a receiving step for receiving the list. A comparison step of comparing the identification number shown in the list received by the reception step with the identification number in the identification number table stored by the storage step. A providing medium comprising providing a computer program having a transmission step of transmitting encrypted data to the third information processing apparatus in response to a comparison result by the comparison step. 【請求項17】 第1の情報処理装置乃至第3の情報処理装置により構成される情報処理システムに用いられるコンピュータプログラムを提供する提供媒体において、 前記第1の情報処理装置は、 秘密裡にしておくべき情報が露呈された前記第3の情報処理装置の識別番号を示したリストを作成する作成ステップと、 前記作成ステップにより作成された前記リストを前記第2の情報処理装置に提供する提供ステップとを備え、 前記第2の情報処理装置は、 所定の伝送路を介して接続されている前記第3の情報処理装置の識別番号を識別番号テーブルとして記憶する記憶ステップと、 前記第1の情報処理装置の前記提供ステップにより提供された前記リストを受信する受信ステップと、 前記受信ステップにより受信された前記リストに示されている前記識別番号と、前記記憶ステップにより記憶された前記識別番号テーブル中の前記識別番号とを比較する比較ステップと、 前記比較ステップによる比較結果に対応して、前記第3の情報処理装置に暗号化データを伝送する伝送ステップとを有するコンピュータプログラムを提供することを特徴とする提供媒体。
Independent claims10
278 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to an information processing device and method, an information processing system, and a providing medium, and in particular, an information processing device and method, an information processing system, and a provision capable of preventing unauthorized copying of data by an unauthorized device. Regarding the medium.
【0002】
[Conventional technology]
Recently, electronic devices such as AV devices and personal computers can be connected to each other via a transmission line such as an IEEE1394 bus (hereinafter, simply referred to as a 1394 bus) so that data can be exchanged between them. A system has been proposed.
【0003】
FIG. 9 shows a configuration example of such an information processing system. In this specification, the system refers to an overall device composed of a plurality of devices. In this example, a DVD (Digital Video Disk) player 1, a personal computer 2, a magneto-optical disk device 3, a data broadcasting receiver 4, a monitor 5, and a television receiver 6 are connected to each other via a 1394 bus 11. There is.
【0004】
FIG. 10 shows a more detailed configuration example inside the DVD player 1, the personal computer 2, and the magneto-optical disk device 3. The DVD player 1 is connected to the 1394 bus 11 via the 1394 interface (I / F) 26. The CPU 21 executes various processes according to the program stored in the ROM 22, and the RAM 23 appropriately stores data and programs necessary for the CPU 21 to execute the various processes. The operation unit 24 is composed of buttons, switches, a remote controller, and the like, and when operated by a user, outputs a signal corresponding to the operation. The drive 25 drives a DVD (disc) (not shown) and plays back the data recorded therein. The EEPROM (electrically erasable programmable ROM) 27 is designed to store information that needs to be stored even after the device is turned off. The internal bus 28 connects each of these parts to each other.
【0005】
The magneto-optical disk device 3 has a CPU 31 and an internal bus 38. These have the same functions as the CPU 21 to the internal bus 28 in the DVD player 1 described above, and the description thereof will be omitted. However, the drive 35 drives a magneto-optical disk (not shown) and records or reproduces data on the disk.
【0006】
The personal computer 2 is connected to the 1394 bus 11 via the 1394 interface 49. The CPU 41 executes various processes according to the program stored in the ROM 42. The RAM 43 appropriately stores data and programs necessary for the CPU 41 to execute various processes. The input / output interface 44 is connected to a keyboard 45 and a mouse 46, and outputs signals input from them to the CPU 41. A hard disk (HDD) 47 is connected to the input / output interface 44, and the CPU 41 can record and play back data, programs, and the like. The input / output interface 44 is also provided with an expansion board 48 as appropriate so that necessary functions can be added. The EEPROM 50 is designed to store information that needs to be retained even after the power is turned off. For example, the internal bus 51 composed of PCI (Peripheral Component Interconnect), local bus, etc. is designed to connect these parts to each other.
【0007】
The internal bus 51 is open to the user, and the user can connect a predetermined board to the expansion board 48 as appropriate, create a predetermined software program, and install the internal bus 51 on the CPU 41. The data transmitted by the bus 51 can be appropriately received.
【0008】
On the other hand, in consumer electronics (CE) devices such as DVD player 1 and magneto-optical disk device 3, the internal bus 28 and internal bus 38 are not open to the user and unless special modifications are made. , It is made so that the data transmitted there cannot be acquired.
【0009】
In the system having the above configuration, for example, when a user watches a movie recorded on a DVD using a display device such as a monitor 5 or a television receiver 6, the DVD player 1 starts from a DVD (disc). The read movie data is transmitted to the display device via the 1394 bus 11, and the display device receives and displays it.
【0010】
By the way, at this time, if the movie data is transmitted as it is via the 1394 bus 11, an unauthorized user may receive the movie data and illegally copy it. Therefore, the device on the transmitting side (hereinafter, such a device is referred to as a source) encrypts and transmits the data to be transmitted, and the device on the receiving side (hereinafter, such a device is referred to as a sink). ) Makes it decrypt using the key. At that time, the device on the transmitting side executes an authentication process with the device before transmitting data in order to determine whether the other device is a legitimate device.
【0011】
The authentication process performed between the source and the sink will be described below. As shown in FIG. 11, this authentication process is performed on the firmware 20 as one of the software programs pre-stored in the ROM 22 of the DVD player 1, for example, and the ROM 42 of the personal computer 2, for example, as the sink. It is stored and is performed with the license manager 62 as one of the software programs processed by the CPU 41.
【0012】
FIG. 12 shows the procedure of authentication performed between the source (DVD player 1) and the sink (personal computer 2). The service key (service_key) and the function (hash) are stored in advance in the EEPROM 27 of the DVD player 1. All of these are given to the users of this DVD player 1 by the copyright holder of the data to be transmitted (movie data), and each user keeps this in the EEPROM 27 in secret. ..
【0013】
The service key is given for each information provided by the copyright holder, and is common in the system composed of the 1394 bus 11. The hash function is a function that outputs fixed-length data such as 64-bit or 128-bit for an arbitrary-length input, and it is difficult to find x when y (= hash (x)) is given. It is also a function that makes it difficult to find the pair of x1 and x2 for which hash (x1) = hash (x2). MD5 and SHA are known as typical one-way hash functions. This one-way hash function is explained in detail in "Applied Cryptography (Second Edition), Wiley" by Bruce Schneier.
【0014】
On the other hand, for example, the personal computer 2 as a sink secretly stores its own unique identification number (device_ID: hereinafter, abbreviated as ID) and license key (license_key) given by the copyright holder in the EEPROM 50. Hold in. This license key is a value obtained by applying a hash function to n + m-bit data (ID The service_key) obtained by concatenating an n-bit ID and an m-bit service key. That is, the license key is expressed by the following equation. license_key = hash (ID The service_key) [0015]
As the ID, for example, node_unique_ID defined in the standard of 1394 bus 11 can be used. As shown in FIG. 12, this node_unique_ID is composed of 8 bytes (64 bits), and the first 3 bytes are managed by the IEEE and given to each manufacturer of electronic devices by the IEEE. Further, the lower 5 bytes can be given by each manufacturer to each device provided to the user by himself / herself. For example, each manufacturer serially assigns one number to each of the lower 5 bytes, and when all 5 bytes are used, the upper 3 bytes are a different number node_unique_ID And assign one number to each of the lower 5 bytes. Therefore, this node_unique_ID will be different for each device regardless of the manufacturer, and will be unique to each device.
【0016】
First, in step S1, the firmware 20 of the DVD player 1 controls the 1394 interface 26 and requests an ID from the personal computer 2 via the 1394 bus 11. The license manager 62 of the personal computer 2 receives the request for this ID in step S2. That is, when the 1394 interface 49 receives the ID request signal transmitted from the DVD player 1 via the 1394 bus 11, it outputs the signal to the CPU 41. When the license manager 62 of the CPU 41 receives this ID request, it reads the ID stored in the EEPROM 50 in step S3 and transmits this from the 1394 bus 11 to the DVD player 1 via the 1394 interface 49.
【0017】
In the DVD player 1, when the 1394 interface 26 receives the ID transmitted from the personal computer 2 in step S4, this ID is supplied to the firmware 20 running on the CPU 21.
【0018】
In step S5, the firmware 20 concatenates the ID transmitted from the personal computer 2 and the service key stored in the EEPROM 27 to generate concatenated data (ID The service_key). Apply the hash function as shown in the formula to generate the key lk. lk = hash (ID The service_key) [0019]
Next, in step S6, the firmware 20 generates the encryption key sk. This encryption key sk is commonly used as a session key in each of the DVD player 1 and the personal computer 2.
【0020】
Next, in step S7, the firmware 20 obtains the encrypted data (encryption key) e by encrypting the encryption key sk generated in step S6 using the key lk generated in step S5 as a key. .. That is, the following equation is calculated. Note that Enc (A, B) is a common key cryptosystem, which means that data B is encrypted by using key A. e = Enc (lk, sk) [0021] [0021]
Next, in step S8, the firmware 20 transmits the encrypted data e generated in step S7 to the personal computer 2. That is, the encrypted data e is transmitted from the 1394 interface 26 of the DVD player 1 to the personal computer 2 via the 1394 bus 11. In the personal computer 2, in step S9, the encrypted data e is received via the 1394 interface 49. The license manager 62 decrypts the encrypted data e received in this way using the license key stored in the EEPROM 50 as a key as shown in the following equation to generate a decryption key sk'. Here, Dec (A, B) means that the data B is decrypted by using the key A in the common key cryptosystem. sk'= Dec (license_key, e) [0022]
DES (Data Encryption Standard) is known as an encryption algorithm in this common key cryptosystem. The common key cryptography is also explained in detail in Applied Cryptography (Second Edition) mentioned above.
【0023】
In the DVD player 1, the key lk generated in step S5 has the same value as the (license_key) stored in the EEPROM 50 of the personal computer 2. That is, the following equation holds. lk = license_key [0024]
Therefore, the key sk'obtained by decryption in step S10 in the personal computer 2 has the same value as the encryption key sk generated in step S6 in the DVD player 1. That is, the following equation holds. sk'= sk [0025]
In this way, the same key sk, sk'can be shared by both the DVD player 1 (source) and the personal computer 2 (sink). Therefore, this key sk can be used as it is as an encryption key, or each can generate a pseudo-random number based on this and use it as an encryption key.
【0026】
As described above, the license key is generated based on the ID unique to each device and the service key corresponding to the information provided, so that no other device can generate sk or sk'. Also, devices not approved by the copyright holder do not have a license key and cannot generate sk or sk'. Therefore, when the DVD player 1 then encrypts the playback data using the encryption key sk and transmits it to the personal computer 2, if the personal computer 2 has properly obtained the license key, the encryption key sk'is used. Since it has, it is possible to decrypt the encrypted playback data transmitted from the DVD player 1. However, if the personal computer 2 is not proper, it cannot decrypt the transmitted encrypted playback data because it does not have the encryption key sk'. In other words, only a proper device can generate a common encryption key sk, sk', and as a result, authentication is performed.
【0027】
Even if the license key of one personal computer 2 is stolen, the IDs are different for each one, so the other devices are encrypted using the license key transmitted from the DVD player 1. The data cannot be decrypted. Therefore, safety is improved.
【0028】
By the way, consider the case where an unauthorized user knows both the encrypted data e and the encryption key sk for some reason. In this case, e is a ciphertext in which the plaintext sk is encrypted with the key lk. Therefore, if the encryption algorithm is open to the public, an unauthorized user obtains the correct key lk by brute force the key lk. there is a possibility.
【0029】
To make this type of attack by unauthorized users more difficult, some or all of the cryptographic algorithms can be kept secret without being disclosed to the public.
【0030】
Or similarly, from license_key, you can keep part or all of the hash function secret without making it publicly available to make the attack of brute force service_key more difficult.
【0031】
FIG. 14 shows an example of processing when not only the personal computer 2 but also the magneto-optical disk device 3 functions as a sink for the source (DVD player 1).
【0032】
In this case, ID1 is stored as the ID and license_key1 is stored as the license key in the EEPROM 50 of the personal computer 2 as the sink 1. In the magneto-optical disk device 3 as the sink 2, the ID2 is stored in the EEPROM 37 as the ID. However, license_key2 is also stored as a license key.
【0033】
The processing of steps S11 to S20 performed between the DVD player 1 (source) and the personal computer 2 (sink 1) is substantially the same as the processing of steps S1 to S10 in FIG. The description is omitted.
【0034】
That is, as described above, the DVD player 1 performs the authentication process on the personal computer 2. Then, in step S21, the DVD player 1 requests an ID from the magneto-optical disk device 3. In the magneto-optical disk device 3, when this ID request signal is received via the 1394 interface 36 in step S22, the firmware 30 (FIG. 18) is stored in the EEPROM 37 in step S23. Is read and transmitted from the 1394 interface 36 to the DVD player 1 via the 1394 bus 11. When the firmware 20 of the DVD player 1 receives this ID2 via the 1394 interface 26 in step S24, the key lk2 is generated from the following equation in step S25. lk2 = hash (ID2 The service_key) [0035]
Further, the firmware 20 calculates the following equation in step S26, encrypts the key sk generated in step S16 using the key lk2 generated in step S25, and generates the encrypted data e2. e2 = Enc (lk2, sk) [0036]
Then, in step S27, the firmware 20 transmits the encrypted data e2 from the 1394 interface 26 to the magneto-optical disk device 3 via the 1394 bus 11.
【0037】
In the magneto-optical disk device 3, in step S28, the encrypted data e2 is received via the 1394 interface 36, and in step S29, the following equation is calculated to generate the encryption key sk2'. sk2'= Dec (license_key2, e2) [0038]
As described above, the encryption keys sk1'and sk2'are obtained in the personal computer 2 and the magneto-optical disk device 3, respectively. These values are the same as the encryption key sk in the DVD player 1.
【0039】
In the processing example of FIG. 14, the DVD player 1 requests the personal computer 2 and the magneto-optical disk device 3 individually for IDs and processes them. If it is possible to request, the processing as shown in FIG. 14 can be performed.
【0040】
That is, in the processing example of FIG. 15, in step S41, the DVD player 1 as a source sends an ID to all sinks (in this example, the personal computer 2 and the magneto-optical disk device 3) by broadcast communication. Request. When the personal computer 2 and the magneto-optical disk device 3 receive the signal of this ID transfer request in step S42 and step S43, respectively, in step S44 or step S45, they read ID1 or ID2 stored in EEPROM50 or EEPROM37, respectively. , Transfer this to DVD player 1. The DVD player 1 receives these IDs in steps S46 and S47, respectively.
【0041】
In the DVD player 1, in step S48, the encryption key lk1 is generated from the following equation. lk1 = hash (ID1 The service_key) [0042]
Further, in step S49, the encryption key lk2 is generated from the following equation. lk2 = hash (ID2 The service_key) [0043]
In the DVD player 1, the encryption key sk is further generated in step S50, and in step S51, the encryption key sk is encrypted using the key lk1 as a key, as shown by the following equation. e1 = Enc (lk1, sk) [0044]
Further, in step S52, the encryption key sk is encrypted according to the following equation using the key lk2 as a key. e2 = Enc (lk2, sk) [0045]
Further, in step S53, ID1, e1, ID2, and e2 are concatenated as shown by the following equations to generate encrypted data e. e = ID1 The e1 The ID2 The e2 [0046]
In the DVD player 1, the encrypted data e generated as described above is further transmitted to the personal computer 2 and the magneto-optical disk device 3 by broadcast communication in step S54.
【0047】
In the personal computer 2 and the magneto-optical disk device 3, these encrypted data e are received in step S55 or step S56, respectively. Then, in the personal computer 2 and the magneto-optical disk device 3, the operations represented by the following equations are performed in step S57 or step S58, respectively, and the encryption keys sk1'and sk2' are generated. sk1'= Dec (license_key1, e1) sk2'= Dec (license_key2, e2) [0048]
FIG. 16 shows an example of processing when one sink can receive a plurality of services (decryption of a plurality of types of information). That is, in this case, for example, the personal computer 2 as a sink stores a plurality of license keys (license_key1, license_key2, license_key3, etc.) in the EEPROM 50. The DVD player 1 as a source stores a plurality of service keys (service_key1, service_key2, service_key3, etc.) in its EEPROM 27. In this case, when the DVD player 1 requests an ID from the personal computer 2 as a sink in step S81, the DVD player 1 transfers a service_ID that identifies the information (service) to be transferred. In the personal computer 2, when this is received in step S82, the one corresponding to this service_ID is selected from the plurality of license keys stored in the EEPROM 50, and the one corresponding to this service_ID is used to perform the decryption process in step S90. I do. Other operations are the same as in FIG.
【0049】
FIG. 17 shows yet another processing example. In this example, the DVD player 1 as a source stores the service_key, the hash function, and the pseudo-random number generator pRNG in its EEPROM 27. These are given by the copyright holder and are kept in secret. Further, the EEPROM 50 of the personal computer 2 as a sink has an ID, LK, LK', a function G, and a pseudo-random number generation function pRNG given by the copyright holder.
【0050】
LK is a unique random number created by the copyright holder, and LK'is generated to satisfy the following equation. LK'= G ^ -1 (R) R = pRNG (H) (+) pRNG (LK) H = hash (ID The service_key) [0051]
Note that G ^ -1 (^ means power) means the inverse function of G. G ^ -1 has a characteristic that it can be easily calculated if a predetermined rule is known, but it is difficult to calculate if it is not known. As such a function, a function used for public key cryptography can be used.
【0052】
Further, the pseudo-random number generation function can be provided as hardware.
【0053】
The DVD player 1 firmware 20 first requests an ID from the license manager 62 of the personal computer 2 in step S101. When the license manager 62 of the personal computer 2 receives the ID request signal in step S102, it reads out the ID stored in the EEPROM 50 and transmits this to the DVD player 1 in step S103. When the firmware 20 of the DVD player 1 receives this ID in step S104, the following equation is calculated in step S105. H = hash (ID The service_key) [0054]
Further, the firmware 20 generates the key sk in step S106, and calculates the following equation in step S107. e = sk (+) pRNG (H) [0055]
Note that A (+) B means an operation of the exclusive OR of A and B.
【0056】
That is, as a result obtained by inputting H obtained in step S105 into the pseudo-random generation key pRNG, the exclusive OR of each bit of the pRNG (H) and the key sk generated in step S106 is calculated. , Encrypt the key SK.
【0057】
Next, in step S108, the firmware 20 transmits e to the personal computer 2.
【0058】
In the personal computer 2, this is received in step S109, and the following equation is calculated in step S110. sk'= e (+) G (LK') (+) pRNG (LK) [0059]
That is, e transmitted from the DVD player 1, the value G (LK') obtained by applying the LK'stored in the EEPROM 50 to the function G stored in the EEPROM 50, and the value G (LK') stored in the EEPROM 50. LK'is applied to the pseudo-random number generator pRNG, which is also stored in EEPROM 50, and the exclusive OR of the result pRNG (LK) is calculated to obtain the key sk'.
【0060】
Here, as shown in the following equation, sk = sk'. sk'= e (+) G (LK') (+) pRNG (LK) = sk (+) pRNG (H) (+) R (+) pRNG (LK) = sk (+) pRNG (H) (+) pRNG (H) (+) pRNG (LK) (+) ) pRNG (LK) = sk [0061]
In this way, the DVD player 1 as a source and the personal computer 2 as a sink can share the same key sk, sk'. Since only the copyright holder can make LK, LK', even if the source illegally tries to make LK, LK', it cannot be made, so it is possible to improve the security.
【0062】
In the above, authentication is performed at the source and the sink, but for example, an arbitrary application program can be normally loaded and used on the personal computer 2. Then, as this application program, an illegally created one may be used. Therefore, for each application program, it is necessary to determine whether or not the permission has been obtained from the copyright holder. Therefore, as shown in FIG. 12, the authentication process can be performed between each application unit 61 and the license manager 62 as described above. In this case, the license manager 62 is the source and the application unit 61 is the sink.
【0063】
Next, as described above, after the authentication is performed (after the encryption key is shared), the encrypted data from the source is transferred to the sink using the encryption key, and this encryption is performed in the sink. The operation when decoding the converted data will be described.
【0064】
As shown in FIG. 18, in a device such as a DVD player 1 or a magneto-optical disk device 3 whose internal functions are not open to general users, the encryption of data exchanged via the 1394 bus 11 is performed. The decoding process is performed on the 1394 interface 26 or the 1394 interface 36, respectively. The session key S and the time-varying key i are used for this encryption and decryption, but the session key S and the time-varying key i (to be exact, the key i'for generating the time-varying key i) are , From firmware 20 or firmware 30, respectively, to 1394 interface 26 or 1394 interface 36. The session key S is composed of an initial value key Ss used as an initial value and a disturbance key Si used to disturb the time-varying key i. The initial value key Ss and the disturbance key Si can be configured by the high-order bits and the low-order bits of a predetermined number of bits of the encryption key sk (= sk') generated in the above-mentioned authentication, respectively. This session key S is updated as appropriate for each session (for example, for each movie information or for each playback). On the other hand, the time-varying key i generated from the disturbance key Si and the key i'is a key that is frequently updated in one session, and for example, time information at a predetermined timing can be used. it can.
【0065】
Now, it is assumed that the video data reproduced and output from the DVD player 1 as a source is transmitted to the magneto-optical disk device 3 and the personal computer 2 via the 1394 bus 11 and decoded in each. In this case, in the DVD player 1, the encryption process is performed on the 1394 interface 26 by using the session key S and the time-varying key i. In the magneto-optical disk device 3, decoding processing is performed on the 1394 interface 36 using the session key S and the time-varying key i.
【0066】
On the other hand, in the personal computer 2, the license manager 62 supplies the initial value key Ss of the session keys S to the application unit 61, and the disturbance key Si and the time-varying key i (to be exact, the time-changing key i). The key i') for generating i is supplied to the 1394 interface 49 (link part). Then, in the 1394 interface 49, the time-varying key i is generated from the disturbance key Si and the key i', decoding is performed using the time-varying key i, and the decoded data is further subjected to the session key in the application unit 61. Decryption is performed using S (precisely, the initial value key Ss).
【0067】
In this way, in the personal computer 2, since the internal bus 51 is open to the user, only the first stage decryption is performed by the 1394 interface 49, and the encrypted state is still maintained. Then, the application unit 61 further performs the second stage decoding to make it plain text. As a result, the personal computer 2 is appropriately added with a function to prohibit copying the data (plaintext) sent and received on the internal bus 51 to the hard disk 47 and other devices.
【0068】
[Problems to be Solved by the Invention]
However, even if the above authentication method is used, for example, a predetermined device is subjected to some processing such as reverse engineering, and information (for example, key information) that should be kept secretly in the device is exposed. If (stolen), there is a problem that the encrypted data may be decrypted using such information.
【0069】
The present invention has been made in view of such a situation, and is intended to prevent data transmission to a device in which information that should be kept secretly is exposed, and to improve safety. Is.
【0070】
[Means for solving problems]
The information processing device according to claim 1 is created to create a list in which the identification number of the first information processing device in which information to be kept secretly is exposed among other information processing devices is described. It is characterized by including means and providing means for providing the list created by the creating means to a second information processing device other than the first information processing device among other information processing devices.
【0071】
The information processing method according to claim 4 is to create a list of other information processing devices in which the identification number of the first information processing device in which information to be kept secretly is exposed is described. It is characterized by including a step and a providing step of providing the list created in the creation step to a second information processing device other than the first information processing device among other information processing devices.
【0072】
The providing medium according to claim 5 is a creation step of creating a list in which the identification number of the first information processing device that reveals the information to be kept secretly among other information processing devices is described. It is characterized by providing a computer program having a providing step of providing the list created in the creation step to a second information processing device other than the first information processing device among other information processing devices. To do.
【0073】
The information processing device according to claim 6 has a storage means for storing the identification numbers of other information processing devices as an identification number table and an identification number of the information processing device in which information to be kept secretly is exposed. A comparison means for comparing the receiving means for receiving the written list, the identification number written in the list received by the receiving means, and the identification number in the identification number table stored by the storage means, and the comparison means. It is characterized in that it is provided with a transmission means for transmitting encrypted data to another information processing device in response to the comparison result according to the above.
【0074】
The information processing method according to claim 13 includes a storage step of storing the identification numbers of other information processing devices as an identification number table and an identification number of the information processing device in which information to be kept secretly is exposed. A comparison step and a comparison step for comparing the reception step for receiving the written list, the identification number written in the list received in the reception step, and the identification number in the identification number table stored in the storage step. Corresponding to the comparison result in the above, it is characterized by including a transmission step of transmitting encrypted data to another information processing device.
【0075】
The providing medium according to claim 14 includes a storage step of storing the identification numbers of other information processing devices as an identification number table, and an identification number of the information processing device in which information to be kept secretly is exposed. In the comparison step and the comparison step in which the reception step for receiving the received list, the identification number written in the list received in the reception step, and the identification number in the identification number table stored in the storage step are compared. It is characterized by providing a computer program having a transmission step of transmitting encrypted data to another information processing device according to the comparison result.
【0076】
The information processing system according to claim 15 is a means for creating a list in which the first information processing device creates a list showing the identification numbers of the third information processing device in which information to be kept secret is exposed. The second information processing device is provided with a providing means for providing the list created by the creating means to the second information processing device, and the second information processing device identifies the identification number of the third information processing device connected via the bus. A storage means for storing as a number table, a receiving means for receiving the list provided by the providing means of the first information processing device, an identification number shown in the list received by the receiving means, and a storage means for storing. It is characterized by comprising a comparison means for comparing the identification numbers in the identified identification number table and a transmission means for transmitting encrypted data to a third information processing apparatus in response to the comparison result by the comparison means. ..
【0077】
The information processing method according to claim 16 includes a creation step in which the first information processing device creates a list showing the identification numbers of the third information processing device in which information to be kept secret is exposed. The second information processing device identifies the identification number of the third information processing device connected via the bus, including the providing step of providing the list created in the creation step to the second information processing device. A storage step for storing as a number table, a receiving step for receiving the list provided in the first information processing apparatus providing step, an identification number shown in the list received in the receiving step, and a storage step for storing. It is characterized by including a comparison step for comparing the identification numbers in the identified identification number table, and a transmission step for transmitting encrypted data to a third information processing apparatus corresponding to the comparison result in the comparison step. ..
【0078】
The providing medium according to claim 17 includes a creation step of creating a list showing the identification numbers of the third information processing apparatus in which information to be kept secret is exposed, and a list created in the creation step. The computer program used in the first information processing device having the providing step provided to the second information processing device and the identification number of the third information processing device connected via the bus are stored as an identification number table. The storage step to be processed, the reception step for receiving the list provided in the first information processing apparatus providing step, the identification number shown in the list received in the reception step, and the identification number stored in the storage step. Used in a second information processing device that has a comparison step that compares the identification numbers in the table and a transmission step that transmits encrypted data to the third information processing device corresponding to the comparison result in the comparison step. It is characterized by providing a computer program that can be processed.
【0079】
In the information processing device according to claim 1, the information processing method according to claim 4, and the providing medium according to claim 5, the information that should be kept secretly among the other information processing devices is A list with the exposed identification numbers of the first information processing device is created, and the created list is sent to the second information processing device other than the first information processing device among other information processing devices. Provided.
【0080】
In the information processing device according to claim 6, the information processing method according to claim 13, and the providing medium according to claim 14, the identification numbers of other information processing devices are stored as an identification number table and are kept secret. A list of information processing device identification numbers that reveals information that should be stored in is received, and the identification numbers in the received list are compared with the identification numbers in the identification number table. , The encrypted data is transmitted to another information processing device according to the comparison result.
【0081】
In the information processing system according to claim 15, the information processing method according to claim 16, and the providing medium according to claim 17, information to be kept secret is exposed in the first information processing apparatus. A list showing the identification number of the third information processing device is created, the created list is provided to the second information processing device, and the second information processing device is connected via a bus. The identification number of the information processing device 3 is stored as an identification number table, the list provided by the first information processing device is received, and the identification number shown in the received list and the identification in the identification number table are received. The numbers are compared, and the encrypted data is transmitted to the third information processing device according to the comparison result.
【0082】
BEST MODE FOR CARRYING OUT THE INVENTION
Embodiments of the present invention will be described below, but in order to clarify the correspondence between each means of the invention described in the claims and the following embodiments, in parentheses after each means, The features of the present invention will be described by adding the corresponding embodiments (provided that they are examples) as follows. However, of course, this description does not mean that each means is limited to the description.
【0083】
The information processing device according to claim 1 is created to create a list in which the identification number of the first information processing device in which information to be kept secretly is exposed among other information processing devices is described. The means (for example, the revocation list creation unit 111 in FIG. 1) and the list created by the creation means are provided to a second information processing device other than the first information processing device among other information processing devices. It is characterized by including a providing means (for example, a transmitting unit 112 of FIG. 1).
【0084】
The information processing apparatus according to claim 2 is further provided with an additional means (for example, the revolving list creation unit 111 of FIG. 1) for adding its own digital signature to the list created by the creator. To do.
【0085】
The information processing device according to claim 6 exposes a storage means (for example, EEPROM 134 in FIG. 1) that stores the identification numbers of other information processing devices as an identification number table, and information that should be kept secretly. The receiving means (for example, the tuner 132 in FIG. 1) for receiving the list on which the identification numbers of the information processing devices are written, the identification numbers written on the list received by the receiving means, and the storage means are stored. A comparison means for comparing the identification numbers in the identification number table (for example, step S207 in FIG. 5) and a transmission means for transmitting encrypted data to another information processing device (for example, corresponding to the comparison result by the comparison means). , The 1394 interface (138) of FIG. 1 is provided.
【0086】
The information processing apparatus according to claim 8 further includes a verification means (for example, step S205 in FIG. 5) for verifying whether or not the list is legitimate by using the signature attached to the list. It is characterized by.
【0087】
The information processing apparatus according to claim 9 flags the corresponding identification number in the identification number table when an identification number matching the identification number in the list exists in the identification number table as a result of comparison of the comparison means. It is characterized by further including additional means for addition (for example, step S209 in FIG. 5).
【0088】
FIG. 1 is a diagram showing a configuration example of an information processing system to which the present invention is applied, and the same reference numerals are given to the parts corresponding to the cases shown in FIG. 9, and the description thereof will be omitted as appropriate. In this configuration example, the management center 110 is created by the revolving list creation unit 111 that creates a list (revocation list) in which the identification numbers of unauthorized devices are described, and the revolving list creation unit 111. It is composed of a transmitter 112 that transmits a revolving list via the antenna 113.
【0089】
When the disclosure of information managed in a predetermined device is discovered, the revolving list creation unit 111 describes a device identification number (device_ID) of the device as a device_ID of an unauthorized device (hereinafter, a revolving list (revocation list)). ) Is created. In addition, the revolving list creation unit 111 creates a revolving list that creates a signature (for example, a digital signature using public key cryptography) indicating that the one that created the revolving list is the management center 110 and the creation time thereof. Add to. This digital signature is used in the device that receives the revolving list to verify whether the revolving list is legitimate. The transmission unit 112 transmits the revolving list created by the revolving list creation unit 111 via the antenna 113 at a predetermined timing. It should be noted that this timing may be, for example, a periodic one once a month, or, for example, a timing when there is a request from another device.
【0090】
The revolving list transmitted from the management center 110 is provided to another device (in this case, the data broadcasting receiving device 130) via, for example, the satellite 120.
【0091】
The data broadcasting receiver 130 is connected to the 1394 bus 11 via the 1394 interface 138. The tuner 132 receives the revolving list transmitted from the management center 110 via the satellite 120 via the antenna 131, and outputs the revolving list to the CPU 133. The CPU 133 executes various processes according to the program stored in the ROM 136, and the RAM 137 appropriately stores data, programs, and the like necessary for the CPU 133 to execute the various processes. The hard disk (HDD) 135 is designed to be able to record or play back data or programs. The EEPROM 134 is designed to store information (for example, a revolving list) that needs to be stored even after the device is turned off. The internal bus 139 connects each of these parts to each other.
【0092】
The detailed configurations of the DVD player 1, the personal computer 2, and the magneto-optical disk device 3 are the same as those shown in FIG.
【0093】
Here, each device connected to the 1394 bus 11 is given a device_ID (for example, node_unique_ID), which is a unique identification number. In addition, among the devices, devices capable of transmitting and receiving data between other devices such as a data broadcasting receiving device 130, a DVD player 1, a personal computer 2, or a magneto-optical disk 3 (hereinafter, particularly these devices). When it is not necessary to distinguish them individually, these devices are appropriately collectively referred to as transmission / reception devices), and devices connected to themselves via the 1394 bus 11 (specifically, at least once for data). An identification number table (connected device_ID table: hereinafter abbreviated as CDT) in which the device_ID of the device of the other party that performed the transmission is described is stored in the EEPROM built in each (for example, in the case of a data broadcasting receiving device, EEPROM 134). (Inside) is prepared in the specified area. Of the devices, the device that cannot transmit data does not need to have a CDT.
【0094】
Each transmitting / receiving device can obtain the device_ID of the other device and store it in the CDT, for example, when performing the authentication process described later with reference to FIG. 8 (of course, other authentication processes may be used). .. Then, each transmitter / receiver confirms the device_ID of the other party (that is, after confirming whether the other device is a legitimate device), and then a key for decrypting the encrypted data (for example, a session key or a session key or). It is designed to decide whether or not to send the time-varying key) to the other device.
【0095】
The data broadcasting receiving device 130 can appropriately read out the device_IDs of all the devices connected to the 1394 bus 11 or the information stored in the CDT of each transmitting / receiving device at a predetermined timing. This timing may be periodic, for example once a week, and if it can be detected that a new device has been added or eliminated from the 1394 bus 11, for example. May be performed at the timing when is detected. Then, the data broadcasting receiving device 130 can reflect the read information in its own CDT (specifically, store a new item).
【0096】
FIG. 2 is a diagram showing a configuration example of a CDT. In this example, addresses 1 to n are the device_ID of the device connected via the 1394 bus 11 and the flag indicating whether or not the device_ID (device_ID described in the revolving list) of the malicious device (device_ID). The revocate flag) is stored. In this example, a flag (x mark) is added to device_IDA to device_IDC at addresses 1 to 3 (specifically, the value indicating the flag is set to 1, for example). That is, the devices corresponding to these device_IDA to device_IDC are considered to be illegal devices.
【0097】
The data broadcast receiver 130 (or other transmitter / receiver) should sort the CDT so that the device_ID containing the flag (ie, the device_ID corresponding to the rogue device) is always placed before the address. It has been done. For example, as shown in FIG. 3, when it is newly discovered that the device corresponding to device_IDF stored at the address 6 is an unauthorized device and a flag is added to the address 6, the data broadcasting receiving device 130 As shown in FIG. 4, the CPU 133 moves the device_IDF stored at the address 6 to the address 4, and moves the device_IDE and device_IDF stored at the addresses 4 and 5 to the addresses 5 and 6, respectively. Let me.
【0098】
It is assumed that n items (for example, 100 items) (device_ID and flag) can be stored in the CDT. However, among the transmitting / receiving devices, the CDT of the management device (in this case, the data broadcasting receiving device 130) that manages the device_ID or CDT of each device using the revolving list provided by the management center 110 is n. It shall be possible to store more than one device_ID and flag. Here, if a new item to be stored in the CDT occurs while all the addresses of this CDT are used, the oldest item in the CDT that is not flagged is deleted. , A new item is stored in the vacant address.
【0099】
For example, there is now a CDT that can store 100 items, and from address 1 to address 10, the items with flags are stored in order from the oldest, and the address 11 Up to address 100, it is assumed that the items to which the flag is not added are stored in order from the oldest one. For example, when a device having this CDT obtains the device_ID of the other device that transmits data for the first time and stores it in the CDT as a new item, it is the oldest item that is not flagged. A certain item at address 11 is deleted, and the items stored at addresses 12 to 100 are moved up one by one (moved to addresses 11 to 99, respectively). Then, a new item is stored in the vacant address 100.
【0100】
Also, for example, when a device with this CDT receives a new revolving list and stores the device_ID in it in the CDT, the item at address 11 is deleted and the device_ID of the revolving list is flagged there. Store with.
【0101】
Further, when this CDT is filled with the flagged items, the device having this CDT has the CDT when the item to be newly stored is the device_ID of the newly received revolving list. When the old item of is deleted and stored in a free address, and it is the device_ID of the remote device that transmitted the data for the first time, it is not stored in the CDT.
【0102】
Next, the operation of the information processing system of FIG. 1 will be described with reference to the flowchart of FIG. In step S201, the revolving creation unit 111 of the management center 110 creates a revolving list indicating the device_ID of the fraudulent device, and then adds a signature and a time to the created revolving list in step S202. In step S203, the transmission unit 112 transmits the revolving list created by the revolving creation unit 111 via the antenna 113 at a predetermined timing.
【0103】
Then, in step S204, the tuner 132 of the data broadcasting receiving device 130 receives the revolving list provided via the satellite 120 via the antenna 131. In step S205, the CPU 133 verifies whether or not the received revolving list is valid. That is, it is verified whether the signature attached to the revolving list belongs to the management center 110. In this verification process, for example, only the device having the public key issued by the management center 110 can confirm the signature.
【0104】
If, in step S205, the revolving list is determined to be invalid (ie, the signature is not that of the control center 110), the CPU 133 discards and processes the revolving list as invalid in step S206. To finish. On the other hand, in step S205, if the revolving list is determined to be valid (that is, the signature belongs to the management center 110), the process proceeds to step S207, and the CPU 133 is recorded in the revolving list. Compare the device_ID of the malicious device with the device_ID in the CDT. In step S208, the CPU 133 determines whether or not a device_ID that matches the device_ID described in the revolving list exists in the CDT, and if it determines that the corresponding device_ID does not exist in the CDT, performs processing. finish.
【0105】
If it is determined in step S208 that a device_ID matching the device_ID listed in the revolving list exists in the CDT, the process proceeds to step S209, and the CPU 133 adds a flag to the corresponding device_ID in the CDT. Subsequently, in step S210, the CPU 133 controls the 1394 interface 138 to send the flagged device_ID in the CDT together with the revolving list to another transmitter / receiver connected via the 1394 bus 11. Send to.
【0106】
Each transmitting / receiving device receives the device_ID and the revolving list flagged with the data broadcasting receiving device 130 in step S211, and determines whether or not the received revolving list is valid in step S212. .. If it is determined in step S212 that the revolving list is not valid (ie, the signature is not that of the control center 110), then in step S213 the revolving list is discarded and processing is terminated.
【0107】
If it is determined in step S212 that the revolving list is valid, the process proceeds to step S214, and each transmitting / receiving device updates (corresponds to) the contents of each CDT in response to the received revolving list. Add a flag to device_ID).
【0108】
By the above processing, the CDTs of all the transmitters / receivers connected to the 1394 bus 11 have been updated corresponding to the revolving list created by the management center 110.
【0109】
Next, based on the above, with reference to FIG. 7, for example, the processing of the DVD player 1 when the personal computer 2 requests the DVD player 1 as the transmission / reception device to transmit data. Will be explained. First, in step S301, the DVD player 1 executes an authentication process (for example, described later with reference to FIG. 8) with the personal computer 2. As a result, the DVD player 1 obtains the device_ID of the personal computer 2. In step S302, it is determined whether or not the device_ID of the personal computer 2 is the device_ID flagged in its own CDT, and the device_ID of the personal computer 2 is flagged in the CDT. If it is determined that, in step S303, the DVD player 1 considers the personal computer 2 to be an unauthorized device and ends the process.
【0110】
If it is determined in step S302 that the device_ID of the personal computer 2 is not flagged in the CDT, the process proceeds to step S304, where the DVD player 1 has the key and encryption with the personal computer 2. Executes data transmission processing. Subsequently, in step S305, the DVD player 1 determines whether the personal computer 2 is a new device (that is, the device that has performed the transmission process for the first time), and the personal computer 2 is a new device. If it is determined that the device is not (that is, the device has already performed the transmission process), the process is terminated.
【0111】
If it is determined in step S305 that the personal computer 2 is a new device (that is, the device that has performed the transmission process for the first time), the process proceeds to step S306, and the DVD player 1 sets the device_ID of the personal computer 2 to CDT. to add. As a result, the data broadcast receiving device 130 obtains the device_ID of the device (in this case, the personal computer 2) newly connected to the 1394 bus 11 when the CDT of the DVD player 1 is read at a predetermined timing. So, for example, if the next received revocation list reveals that this personal computer 2 is a rogue device, it can be sent to each transmitter / receiver (excluding personal computer 2) connected to the 1394 bus 11. By notifying, it becomes possible to substantially eliminate the personal computer 2.
【0112】
As described above, each transmission / reception device can determine whether or not the other device is an illegal device in response to the revolving list provided by the management center 110, and can transmit data such as a movie. Can be done safely.
【0113】
FIG. 8 is a timing chart showing an example of authentication processing executed in step S301 of FIG. In this example, the service key (service_key) and the hash function (F, G, H) are stored in advance in the EEPROM 27 of the DVD player 1 as the source. On the other hand, the personal computer 2 as a sink secretly holds its device_ID (ID), license key (license_key), and hash function (G, H) in the EEPROM 50. First, in step S111, the personal computer 2 generates a random number Nb. Then, in step S112, the 1394 interface 49 is controlled to transmit the authentication request to the DVD player 1 via the 1394 bus 11 together with the generated random number Nb.
【0114】
The DVD player 1 receives this authentication request and the random number Nb in step S113. Next, the DVD player 1 requests the device_ID from the personal computer 2 in step S114. The personal computer 2 receives the request for device_ID in step S115, and in response to this, reads the device_ID recorded in the EEPROM 50 in step S116 and transmits it to the DVD player 1. As a result, the DVD player 1 can obtain the device_ID of the personal computer 2.
【0115】
In step S117, the DVD player 1 receives the device_ID transmitted from the personal computer 2, and in step S118, the received ID is set in the hash function F using the service key (Kser) as a key, as shown in the following equation. Generate data Kv by applying. Note that keyedhashA1 (A2, A3) indicates that A3 is applied to the hash function A1 whose key is A2. Kv = keyedhashF (Kser, ID) [0116]
Next, the DVD player 1 generates a random number Na in step S119, and transmits the random number Na to the personal computer 2 in step S120. The personal computer 2 receives the random number Na in step S121, and in step S122, as shown in the following equation, the data (NaTheNb) in which the random number Na and the random number Nb are concatenated with the hash function H using the license key Klic as the key. ) Is applied to generate data R. R = keyedhashH (Klic, NaTheNb) [0117]
Then, the personal computer 2 transmits the generated data R to the DVD player 1 in step S123. The DVD player 1 receives the data R in step S124, and in step S125, the value obtained by applying the concatenated data (NaTheNb) to the hash function H using the data Kv generated in step S118 as the key. Determines if is equal to the received data R.
【0118】
If it is determined in step 125 that the two are not equal, the received data R is discarded and the authentication process is terminated (that is, the personal computer 2 is determined to be inappropriate). On the other hand, if it is determined in step 125 that both are equal, the process proceeds to step S126, and the DVD player 1 inputs the concatenated data (NaTheNb) to the hash function G using the data Kv as the key, as shown in the following equation. Generate a key Kab by applying. Kab = keyedhashG (Kv, NaTheNb) [0119]
This key Kab is a key temporarily used between the DVD player 1 and the personal computer 2. For example, when a magneto-optical disk device 3 is connected as a sink to the DVD player 1 as a source in addition to the personal computer 2, the key used between the DVD player 1 and the magneto-optical disk device 3 is further separated. It will be generated.
【0120】
Next, in step S127, the DVD player 1 generates a key Kc that is commonly used in the session, and in step S128, the key Kc is encrypted using the key Kab to encrypt data (encryption key) X. To generate. That is, the following equation is calculated. Enc (B1, B2) indicates that B2 is encrypted using B1 as a key. X = Enc (Kab, Kc) [0121]
Then, in step S129, the DVD player 1 transmits the encrypted data X to the personal computer 2. In step S130, the personal computer 2 receives the encrypted data X transmitted from the DVD player 1, and in step S131, applies the concatenated data (NaTheNb) to the hash function G with the license key Klic as the key. By doing so, the key K'ab is generated. That is, the following equation is calculated. K'ab = keyedhashG (Klic, NaTheNb) [0122]
Then, in step S131, the personal computer 2 decodes the data X using the key K'ab as shown in the following equation to obtain the key Kc. Note that Dec (C1, C2) indicates that C2 is decoded using C1 as a key. Kc = Dec (K'ab, X) [0123]
Thereby, for example, even when there are a plurality of devices as sinks, the same key Kc can be safely shared between the source and all the sinks.
【0124】
Then, the firmware 20 of the DVD player 1 generates a random number N'a in step S121, and transmits the random number N'a to the personal computer 2 in step S133. The license manager 62 of the personal computer 2 receives the random number N'a in step S134. Then, the firmware 20 of the DVD player 1 and the license manager 62 of the personal computer 2 both obtain the session key sk by calculating the following equations using the key Kc and the random number N'a in step S135 and step S136, respectively. obtain. sk = keyedhashH (Kc, N'a) [0125]
When changing the session key, the source generates a new random number, sends it to all the devices that will be the sink, and each device uses the new random number to generate the session key. To.
【0126】
By the way, in the above processing, in order to enable each transmitting / receiving device to confirm the validity of the revolving list, the data broadcasting receiving device 130, which is a management device, transmits the received revolving list to each transmitting / receiving device. Although it is designed to be transmitted, if the data size of the revolving list is large, the communication cost is expected to be high. Therefore, the following two methods can be considered as countermeasures. (1) When the management center 110 creates a revolving list, it divides it into a predetermined number, adds a signature to each of the divided lists, and attaches it to a management device such as a data broadcasting receiving device 130. In addition, the management device such as the data broadcasting receiving device 130 is connected only to the device related to the device connected to itself from the revolving list provided by the management center 110. To transmit to the transmitter / receiver. (2) The management device such as the data broadcasting receiver 130 is provided with a function to create a digital signature, extracts the part included in the CDT from the revocation list, and renews the revocation list for the network. Create it, add a signature to it, and transmit it to other connected transmitters and receivers.
【0127】
A program or revocation list that executes the above various commands is required to be provided to the user via a transmission medium such as a magnetic disk or a CD-ROM, or to the user via a transmission medium such as a network. Depending on the situation, it can be stored in the built-in RAM, hard disk, etc. for use.
【0128】
[Effect of the invention]
As described above, according to the information processing device according to claim 1, the information processing method according to claim 4, and the providing medium according to claim 5, the information processing device is stored in secret among other information processing devices. Create a list with the identification number of the first information processing device that reveals the information to be kept, and use the created list as the second of the other information processing devices other than the first information processing device. Since it is provided to the information processing device of the above, it is possible to inform other devices of the device_ID of the device in which the information to be kept secretly is exposed.
【0129】
According to the information processing device according to claim 6, the information processing method according to claim 13, and the providing medium according to claim 14, the identification numbers of other information processing devices are stored as an identification number table and kept secret. Receive a list of information processing device identification numbers that reveal information that should be stored, and compare the identification numbers in the received list with the identification numbers in the identification number table. However, since the encrypted data is transmitted to other information processing devices according to the comparison result, the data is not transmitted to the device that reveals the information that should be kept secretly. Can be done.
【0130】
According to the information processing system according to claim 15, the information processing method according to claim 16, and the providing medium according to claim 17, the first information processing apparatus exposes information to be kept secret. A list showing the identification number of the third information processing device is created, the created list is provided to the second information processing device, and the second information processing device is connected via a bus. The identification number of the third information processing device is stored as an identification number table, the list provided by the first information processing device is received, and the identification number shown in the received list and the identification number in the identification number table are stored. Since the encrypted data is transmitted to the third information processing device according to the comparison result with the identification number, the data to the device where the information that should be kept secretly is exposed. It is possible to improve the safety by preventing the transmission of information processing.
[Simple explanation of drawings]
[Figure 1]
It is a block diagram which shows the structural example of the information processing system to which this invention is applied.
[Figure 2]
It is a figure which shows the structural example of a CDT.
[Fig. 3]
It is a figure which shows a state that a new device_ID is added to the CDT of FIG.
[Fig. 4]
It is a figure explaining the process of sorting the address of CDT.
[Fig. 5]
It is a flowchart explaining the process of the information processing system of FIG.
[Fig. 6]
It is a figure following FIG.
[Fig. 7]
It is a flowchart explaining the process of a DVD player 1.
[Fig. 8]
It is a timing chart explaining the authentication process of step S301 of FIG.
[Fig. 9]
It is a block diagram which shows the configuration example of the conventional information processing system.
[Fig. 10]
It is a block diagram which shows the internal structure example of the DVD player 1, the personal computer 2, and the magneto-optical disk apparatus 3 of FIG.
[Fig. 11]
It is a figure explaining the authentication process.
[Fig. 12]
It is a timing chart explaining an authentication process.
[Fig. 13]
It is a figure which shows the format of node_unique_ID.
[Fig. 14]
It is a timing chart explaining other authentication processing.
[Fig. 15]
It is a timing chart explaining other authentication processing.
[Fig. 16]
It is a timing chart explaining other authentication processing.
[Fig. 17]
It is a timing chart explaining other authentication processing.
[Fig. 18]
It is a block diagram explaining an encryption process.
[Explanation of symbols]
1 DVD player, 2 personal computer, 3 magneto-optical disk device, 11 1394 bus, 110 management center, 111 recitation list creator, 112 tuner, 113 antenna, 120 satellite, 130 data broadcast receiver, 131 antenna, 132 tuner, 133CPU, 134 EEPROM, 135 hard disk, 136 ROM, 137 RAM, 138 1394 antenna, 139 internal bus
19 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO03015344A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP4841095B2 | Cited by | Japan | Examiner |
| WO0115380A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7761926B2 | Cited by | United States of America | Applicant |
| JP2002135243A | Cited by | Japan | Search report |
| US8458458B2 | Cited by | United States of America | Applicant |
| US7657739B2 | Cited by | United States of America | Applicant |
| US7404076B2 | Cited by | United States of America | Applicant |
| US8190886B2 | Cited by | United States of America | Applicant |
| WO0233880A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| KR100896390B1 | Cited by | Republic of Korea | Search report |
| WO0115380A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2002135243A | Cited by | Japan | Examiner |
| WO0233880A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7636843B1 | Cited by | United States of America | Applicant |
| JP4524920B2 | Cited by | Japan | Examiner |
| JP2002152187A | Cited by | Japan | Search report |
| US9759082B2 | Cited by | United States of America | Applicant |
| US7739495B2 | Cited by | United States of America | Applicant |
| US9390254B2 | Cited by | United States of America | Applicant |
| US7224804B2 | Cited by | United States of America | Applicant |
| JP2004096755A | Cited by | Japan | Examiner |
| CN100413246C | Cited by | China | Search report |
| WO2005052802A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2009157675A | Cited by | Japan | Examiner |
| US8051284B2 | Cited by | United States of America | Applicant |
| JP2002344834A | Cited by | Japan | Examiner |
| WO0239655A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2003512786A | Cited by | Japan | Examiner |
| JP2011086313A | Cited by | Japan | Examiner |
| WO2004086235A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JPH0696098A | Cites | Japan | Examiner |
| JPH0785172A | Cites | Japan | Examiner |
| JPH09107350A | Cites | Japan | Examiner |
| JPH09128336A | Cites | Japan | Examiner |
| JPH0991133A | Cites | Japan | Examiner |
| JPS61188666A | Cites | Japan | Examiner |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 403098 | Japan | A | |
| JP19980004030 | – | – | – |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesR250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Request for written amendment filedA521 | A521 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 11-205305
- Publication, DOCDB
- H11205305
- Publication, EPODOC
- JPH11205305
- Application
- 10004030
- Application, DOCDB
- 403098
- Application, EPODOC
- JP19980004030
Titles3
- English
- [Title of Invention] Information processing apparatus and method, information processing system, and providing medium.
- Japanese
- 【発明の名称】情報処理装置および方法、情報処理システム、並びに提供媒体
- English
- INFORMATION PROCESSING UNIT AND METHOD, INFORMATION PROCESSING SYSTEM AND SERVING MEDIUM
Classification
- CPC, 12
- G11B20/00086
- G06F21/10
- G06F2221/0771
- G11B20/0021
- H04L63/101
- H04L2463/101
- H04N21/25816
- H04N21/2585
- H04N21/43615
- H04N21/6143
- H04N21/835
- G06F21/1076
- IPC, 22
- G06F1 00
- G06F12 14
- G06F21 00
- G06F21 10
- G06F21 31
- G06F21 60
- G06F21 62
- G06F21 64
- G11B20 00
- H04L9 10
- H04L9 32
- H04L9 36
- H04L29 06
- H04N5 765
- H04N5 91
- H04N21 258
- H04N21 436
- H04N21 442
- H04N21 4627
- H04N21 61
- H04N21 6334
- H04N21 835