Device-independent management of cryptographic information
Abstract
Some embodiments provide an account-based DRM system for distributing content. The system includes several devices that are associated with one particular account. The system also includes a set of DRM computers that receives a request to access a particular piece of content on the devices associated with the particular account. The DRM computer set then generates a several keys for the devices, where each particular key of each particular device allows the particular device to access the particular piece of content on the particular device. Through a network, the DRM computer set of some embodiments sends the particular piece of content and the generated keys to the devices associated with the particular account. The network is a local area network, a wide area network, or a network of networks, such as the Internet. In some of these embodiments, the DRM computer set sends the content and keys to one device (e.g., a computer), which is used to distribute the content and the key(s) to the other devices associated with the account. In some embodiments, the DRM computer set individually encrypts each key in a format that is used during its transport to its associated device and during its use on this device.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
67 claims: 13 independent, 54 dependent
- 1CLAIMS PATENTKRAV 1. En metod för tillhandahållande av nycklar för access till en datamängd innefattande:generering av ett flertal olika nycklar för access till en speciell datamängd på ett flertal samhörande enheter;och tillhandahållande av de genererade nycklarna till åtminstone en speciell enhet av de samhörande enheterna, för att möjliggöra för den speciella enheten att använda åtminstone en nyckel för den speciella enheten för access till den speciella datamängden på den speciella enheten, extrahera vage nyckel för vage annan enhet av de samhörande enheterna från den genererade uppsättningen nycklar, och tillhandahålla de extraherade nycklarna till de andra enheterna. 1st A method of providing keys for accessing a data set comprising: generating a plurality of different keys for accessing a particular data set on a plurality of associated units;and providing the generated keys to at least one particular unit of the associated units, to enable the particular unit to use at least one key for the particular unit to access the particular amount of data on the particular unit, extracting the vague key for the vague other unit of the associated units from the generated set of keys, and providing the extracted keys to the other units.
- 8Ett datorläsbart medium lagrande ett program vilket vid exekvering tillhandahåller nycklar för access till en datamängd, varvid programmet innefattar uppsättningar av instruktioner för:Eighth A computer-readable medium storing a program which, upon execution, provides keys for access to a data set, the program comprising sets of instructions for: 534 641 tb generating a plurality of different keys for accessing a particular amount of data on a plurality of associated units including a particular unit;and providing the generated keys to the particular unit, to enable the particular unit to use at least one key of the particular unit for accessing the particular amount of data on the particular unit, extracting each key for each other unit of the associated units from it generated the majority of keys, and provide the extracted keys to the other devices. 534 641 tb generering av ett flertal olika nycklar för access till en speciell datamängd på ett flertal samhörande enheter inkluderande en speciell enhet;och tillhandahållande av de genererade nycklarna till den speciella enheten, för att möjliggöra för den speciella enheten att använda åtminstone en nyckel för den speciella enheten för access till den speciella datamängden på den speciella enheten, extrahera varje nyckel för varje annan enhet av de samhörande enheterna från det genererade flertalet av nycklar, och tillhandahålla de extraherade nycklarna till de andra enheterna.
- 14En metod för tillhandahållande av nycklar för access till en datamängd innefattande:individuell kryptering av ett flertal olika nycklar för access till en enda datamängd på ett flertal samhörande enheter;och tillhandahållande av de individuellt krypterade nycklama tillsammans till en speciell enhet av de samhörande enheterna varvid den speciella enheten är avsedd att distribuera nycklama individuellt till de andra enheterna. 14th A method of providing keys for accessing a data set comprising: individually encrypting a plurality of different keys for accessing a single data set on a plurality of associated units;and providing the individually encrypted keys together to a particular unit of the associated units, the particular unit being designed to distribute the keys individually to the other units. 534 641 /7 534 641 /7
- 20Ett datorläsbart medium lagrande ett program, vilket vid exekvering tillhandahåller nycklar för access till en datamängd, varvid programmet innefattar uppsättningar av instruktioner för:20th A computer-readable medium storing a program, which upon execution provides keys for access to a data set, the program comprising sets of instructions for: mottagning av en begäran om en datamängd;och leverans till en första enhet av datamängden i en krypterad form tillsammans med en första nyckel för access till datamängden på den första enheten och en andra nyckel, skild från den första nyckeln, för access till datamängden på en andra enhet varvid den första enheten är avsedd att leverera datamängden i den krypterade formen och den andra nyckeln, utan den första nyckeln, till den andra enheten för att medge att den andra enheten får access till datamängden. receiving a request for a data set;and delivery to a first unit of the data set in an encrypted form together with a first key for accessing the data set of the first unit and a second key, so-called from the first key, for accessing the data set of a second unit, the first unit being intended to deliver the data set in the encrypted form and the second key, without the first key, to the second device to allow the second device to access the data set.
- 26En metod för access till en datamängd innefattande:26th A method of accessing a data set comprising: on a first unit, receiving an encrypted key in a data storage structure, the encrypted key being intended for access to a data set on the first unit, the data storage structure also storing at least one additional encrypted key for accessing a data set on a second unit;and storing the encrypted key in the device in the same format as the encrypted key stored in the data storage structure. på en första enhet mottagning av en krypterad nyckel i en datalagringsstruktur, varvid den krypterade nyckeln är avsedd för access till en datamängd på den första enheten, varvid datalagringsstrukturen också lagrar åtminstone en ytterligare krypterad nyckel för access till en datamängd på en andra enhet.;och lagring av den krypterade nyckeln i enheten i samma format som den krypterade nyckeln lagrats i datalagringsstrukturen.
- 28Ett läsbart lagringsmedium på en första enhet, vilket lagrar ett program, vilket vid exekvering mottager nycklar för access till en datamängd, varvid programmet innefattar uppsättningar av instruktioner för:28th A readable storage medium on a first unit, which stores a program, which upon execution receives keys for access to a data set, the program comprising sets of instructions for: sending a request for a data set;and receiving the data set, a first key for accessing the data set on the first unit, and a second key for accessing the data set on a second unit, the second key being intended for later distribution, without the first key, from the first unit to the other device. utsändande av en begäran för en datamängd;och mottagande av datamängden, en första nyckel för access till datamängden på den första enheten, och en andra nyckel för access till datamängden på en andra enhet, varvid den andra nyckeln är avsedd för senare distribution, utan den första nyckeln, från den första enheten till den andra enheten.
- 34En metod innefattande:mottagande av ett flertal datamängder av en speciell enhet;mottagande av en första datalagringsstruktur innefattande ett flertal individuellt krypterade nycklar för access till en av datamängderna på ett flertal olika enheter;och lagring i en andra datalagringsstruktur i den speciella enheten var och en av nycklarna för de olika enheterna i det individuellt krypterade formatet för den första datalagringsstrukturen, varvid den andra datalagringsstrukturen också lagrar ett flertal individuellt krypterade nycklar för access till en andra av flertalet datamängder på flertalet olika enheter. 34th A method comprising: receiving a plurality of data sets by a particular unit;receiving a first data storage structure comprising a plurality of individually encrypted keys for accessing one of the data sets on a plurality of different devices;and storing in a second data storage structure in the particular unit each of the keys of the various units in the individually encrypted format of the first data storage structure, the second data storage structure also storing a plurality of individually encrypted keys for access to a second of the plurality of data sets on the plurality different units.
- 35Ett läsbart lagringsmedium på en speciell enhet, varvid det läsbara lagringsmediet lagrar ett program för exekvering och programmet innefattar uppsättningar av instruktioner för:35th A readable storage medium on a particular device, wherein the readable storage medium stores a program for execution and the program includes sets of instructions for: mottagande av ett flertal datamängder;receiving a plurality of data sets;mottagande av en första datalagringsstruktur innefattande ett flertal individuellt krypterade nycklar för access till en av datamängderna på ett flertal olika enheter, inklusive den speciella enheten;receiving a first data storage structure comprising a plurality of individually encrypted keys for access to one of the data sets on a plurality of different units, including the particular unit;lagring i en andra datalagringsstruktur i den speciella enheten var och en av nycklarna för de olika enheterna i det individuellt krypterade formatet för den första datalagringsstrukturen, varvid den andra datalagringsstrukturen också lagrar ett flertal storing in a second data storage structure in the particular unit each of the keys for the various units in the individually encrypted format of the first data storage structure, the second data storage structure also storing a plurality of 534 641 534 641 Λ0 individually encrypted keys for access to a second of the plurality of data sets on the plurality of different devices;and using a key stored in the second data storage structure to gain access to the data set. Λ0 individuellt krypterade nycklar for access till en andra av flertalet datamängder på flertalet olika enheter;och användning av en nyckel lagrad i den andra datalagringsstrukturen för att fa access till datamängden.
- 36Ett digitalt rättsförvaltande system för distribution av information, varvid systemet innefattar:36th A digital law-management system for the distribution of information, the system comprising: a plurality of entities associated with an account;and a set of DRM computers for receiving a request for access to a particular amount of data on the devices associated with the account and generating a set of a plurality of different keys for said device, each key for each device permitting the device to access the particular the amount of data on the unit, wherein the set of generated keys is intended for distribution to a particular unit of the plurality of units;which extracts the key for each other device from the generated set of keys and delivers only the extracted key to the other device. ett flertal enheter associerade med ett konto;och en uppsättning DRM-datorer för mottagning av en begäran om access till en speciell datamängd på enheterna associerade med kontot och generering av en uppsättning av ett flertal olika nycklar för nämnda enheter, varvid vaije nyckel för vaije enhet medger att enheten far access till den speciella datamängden på enheten, varvid uppsättningen av genererade olika nycklar är avsedda för distribution till en speciell enhet av flertalet enheter, vilken extraherar nyckeln för vaije annan enhet från den genererade uppsättningen av nycklar och levererar endast den extraherade nyckeln till den andra enheten.
- 41En metod för tillhandahållande av nycklar för access till en datamängd innefattande:fastställande av att en ny enhet har specificerats för access till data associerad med ett speciellt konto;41st A method of providing keys for accessing a data set comprising: determining that a new device has been specified for accessing data associated with a particular account;534 641 534 641 Λ / generation of a separate key for the new device for each data set associated with the particular account;and providing any key generated. Λ/ generering av en separat nyckel för den nya enheten för varje datamängd associerad med det speciella kontot;och tillhandahållande av vaije genererad nyckel.
- 48Ett datorläsbart medium lagrande ett program, vilket vid exekvering tillhandahåller nycklar för access till en datamängd, varvid programmet innefattar uppsättningar av instruktioner för:48th A computer-readable medium storing a program, which upon execution provides keys for access to a data set, the program comprising sets of instructions for: determining that a new entity has been specified for access to data associated with a particular account;fastställande av att en ny enhet har specificerats för access till data associerad med ett speciellt konto;generating a separate key for the new device for each data set associated with the particular account;and providing the key generated key to a second device associated with the particular account, the second device being intended to deliver the keys to the new device. generering av en separat nyckel för den nya enheten för varje datamängd associerad med det speciella kontot;och tillhandahållande av vaqe genererad nyckel till en andra enhet associerad med det speciella kontot, varvid den andra enheten är avsedd att leverera nycklarna till den nya enheten. 534 641 534 641
- 56En metod innefattande:56th A method comprising: sending a request for a data set from a first unit;receiving in a first unit of the data set, a first key for accessing the data set on the first unit and a second key, separate from the first key for accessing the data set on a second unit;and providing from the first unit of the second key, but the first key to the second unit, to allow the second unit to access the data set. utsändning av en begäran om en datamängd från en första enhet;mottagning i en första enhet av datamängden, en första nyckel för access till datamängden på den första enheten och en andra nyckel, skild från den första nyckeln för access till datamängden på en andra enhet;och tillhandahållande från den första enheten av den andra nyckeln, utan den första nyckeln till den andra enheten, för att medge att den andra enheten far access till datamängden.
- 60En digital rättsförvaltande metod för distribution av en datamängd till en användare, varvid metoden innefattar följande steg:60th A digital law management method for distributing a data set to a user, the method comprising the following steps: mottagning av en begäran från användaren avseende datamängden, varvid användaren har ett flertal associerade enheter för åtkomst av datamängden;receiving a request from the user regarding the data set, wherein the user has a plurality of associated entities for accessing the data set;broadcasting to a first unit associated with the user of the requested data set in a protected format;utsändning till en första enhet associerad med användaren av den begärda datamängden i ett skyddat format;generating for each particular device associated with the user of a separate key for accessing the amount of data on the device;generering för varje speciell enhet associerad med användaren av en separat nyckel för access till datamängden på enheten;lagring av de genererade nycklama i en första datalagringsstruktur för distribution till användaren;och utsändning från en uppsättning DRM-datorer till den första enheten associerad med användaren av den första datalagringsstrukturen, som lagrar de genererade nycklarna, för access till datamängden på flertalet associerade enheter, varvid en första nyckel lagrad i datalagringsstrukturen är avsedd för access till datamängden på den första enheten, och den första enheten är avsedd för extrahering av nycklama från den första datalagringsstrukturen och distribution till vaije speciell andra associerad enhet av datamängden i det skyddade formatet och endast den respektive nyckeln för access till datamängden på den speciella associerade enheten. storing the generated keys in a first data storage structure for distribution to the user;and transmitting from a set of DRM computers to the first unit associated with the user of the first data storage structure storing the generated keys for access to the data set on the plurality of associated devices, a first key stored in the data storage structure being intended for accessing the data set on the first unit, and the first unit is intended for extracting the keys from the first data storage structure and distributing to each particular second associated unit of the data set in the protected format and only the respective key for accessing the data set of the particular associated unit.
Independent claims13
92 paragraphs in 12 sections, as filed
(12) Patent Specification do) SE 534 641 C2
<img file="SE534641C2_D0001.tif" />
Sweden (21) Patent application number: 0950201-4 (45) Patent granted: 2011-11-01 (41) Application generally available: 31 March 2009 (22) Patent application submitted: 2007-05-03 (24) Maturity date: 2007- 05-03 (62) Stock application number: 0701065-5 (83) Deposit of microorganism: - (30) Priority information: 2006-05-03 US 11/381486 (51) International class:
G06F 21/22 (2006.01)
H04L 9/08 (2006.01)
<td>(73) Patent holders:</td><td>APPLE INC., M / S 3-PAT, 1 Infinite Loop, CA 95014 Cupertino US</td>
<td>(72) Inventor:</td><td>Augustin J Farrugia, Cupertino US Gianpaolo Fasoli, Palo Alto US Jean-Francois Riendeau, Cupertino US</td>
<td>(74) Agents:</td><td>Hynell Patenttjänst AB, Box 138, 683 23 HAGFORS SE</td>
<td>(54) Name:</td><td>Device-independent processing of encrypted information</td>
<td>(56) Publications cited:</td><td>US 20050102513 Al</td>
(47) Summary:
Some embodiments provide an account-based DRM system for distributing information. The system includes a number of units associated with a particular account. The system also includes a set of DRM computers, which receive a request for access to a particular set of information on the devices associated with the particular account. The set of DRM computers then generates a number of keys for the devices, whereby each individual key to each individual device allows the particular device to access the particular amount of data on the particular device. The set of DRM computers in some embodiments transmits the particular amount of data and the generated keys through a network to the devices associated with the particular account. The network is a LAN, a WAN or a network of networks, such as the Internet. In some of these embodiments, the set of DRM computers transmits the amount of data and keys to a device (for example, a computer), which is utilized to distribute the data amount and key (s) to the other devices associated with the account. In some embodiments, the set of DRM computers individually encrypts each key in a format used during its transport to the associated device and during use in that device.
534 641
SUMMARY OF THE INVENTION
Some embodiments provide an account-based DRM system for distributing information. The system includes a number of units associated with a particular account. The system also includes a set of DRM computers, which receive a request for access to a particular set of information on the devices associated with the particular account. The set of DRM computers then generates a number of keys for the devices, with each individual key for each individual device allowing the particular device to access the particular amount of data on the particular device. The set of DRM computers in some embodiments transmits the particular amount of data and the generated keys through a network to the devices associated with the particular account. The network is a LAN, a WAN or a network of networks, such as the Internet. In some of these embodiments, the set of DRM computers transmits the amount of data and keys to a device (for example, a computer), which is utilized to distribute the data amount and key (s) to the other devices associated with the account. In some embodiments, the set of DRM computers individually encrypts each key in a format used during its transport to the associated device and during use in that device.
534 641 i
DEVICE PROCESSING OF Cryptographed Information
TECHNICAL FIELD
The invention relates to device independent processing of encrypted information.
BACKGROUND OF THE ART
The protection of digital data transmitted between computers over a network is fundamentally important for many companies today. Companies are trying to achieve this protection by implementing some form of Digital Rights Management (DRM) procedure. The DRM method often involves encrypting the information (eg, encrypting the binary form of the information) to limit its use to the persons who have been authorized to use it.
Encryption is the traditional method of protecting data during transmission in a network. In its typical application, encryption protects communications between two parties with mutual trust from theft by attacking the data flow during transmission. For many digital file transfer applications today (e.g. for transmitting audio or video information), however, the paradigm has shifted, since a party receiving the information (i.e., the "receiving party") may attempt to break the DRM encryption as the party providing the information (i.e., the "sending party") has applied to the information. Moreover, with the spread of network attacks, a third party can gain access to the receiving party's computer and thus to the protected information.
In many DRM systems today, the weakest link in security is not the encrypted data flow but rather the processing and handling of the encryption key. For example, one of the more successful DRM systems, which distribute music online, requires the receiving party's computer to store the unencrypted key for each piece of encrypted music in the "Key Bag", which is encrypted.
This solution has two disadvantages. First, by encrypting the Keybag instead of the keys in the Keybag, this procedure exposes the keys to a potential attack at different times. Each time the receiving party's computer stores a new key for an amount of information, for example, the computer must decrypt the entire
534 641
The key bag, add the new key to the key bag and then re-encrypt the key bag. Similarly, in order to play a piece, the receiving party's computer must decrypt the entire Key Case, find the key for the piece, and decrypt the piece using this key. In each of these situations, all the keys are exposed to a potential attacker when the Keybag is decrypted.
Secondly, this previously known DRM method allows different devices to utilize different formats for their key bags. It allows, for example, the receiving party's computer to use a different format for the Key Case than a music player to which the computer downloads its music. The use of different formats for the Key Case for different devices also exposes the keys for decrypting the information transmitted between the devices. For example, when the receiving party synchronizes the music player's music library with the computer, the computer must decrypt its Key Case and transfer the synchronized data set and its associated keys to the music player. The music player then stores the received amount of data in a storage device and stores the received keys in the player's special format in the player's key bag. During this transfer, all the keys are exposed to a possible attacker.
Therefore, there is a need in this technology area of a DRM system, which minimizes the exposure of encryption keys at different stages of the DRM process. Such a system should minimize exposure during the local storage of the encryption keys in the devices that use such keys to decrypt and access information. This system should also minimize the encryption key exposure while the encrypted information is read by a receiving device. Furthermore, this system should minimize the exposure of the encryption keys while the receiving device transmits information between two devices.
SUMMARY OF THE INVENTION
Some embodiments provide an account-based DRM system for distributing information. The system includes a number of units associated with a particular account. The system also includes a set of DRM computers, which receive a request for access to a particular set of information on the devices associated with the particular account. The set of DRM computers then generates a number of keys for the devices, whereby each individual key to each individual device allows the particular device to access the particular amount of data on the particular device.
534 641
The set of DRM computers in some embodiments transmits the particular amount of data and the generated keys through a network to the devices associated with the particular account. The network is a LAN, a WAN or a network of networks, such as the Internet. In some of these embodiments, the set of DRM computers transmits the amount of data and keys to a device (for example, a computer), which is utilized to distribute the data amount and key (s) to the other devices associated with the account. In some embodiments, the set of DRM computers individually encrypts each key in a format used during its transport to the associated device and during use in that device.
Some embodiments provide a digital law management method (DRM) for the distribution of a data set to a user. The user has at least two devices for accessing the information. The method sends the information to the user in a protected format. From the set of DRM computers, the method also sends to the user (1) a first key that allows the user to access the protected information on the first device, and (2) a second key that allows the user to access the protected information on the other device.
In some embodiments, the first and second keys are used to decrypt the information. In other embodiments, the first and second keys are used to decrypt an additional key or keys used to encrypt the information. In some embodiments, the method individually encrypts the first and second keys before sending them to the first and second units.
Additionally, in some embodiments, the first device is a user computer and the second device is another device (for example, a portable media player) that synchronizes its information with the user computer. In some of these embodiments, (1) the user computer receives the information and the first and second key and (2) then provides the received information and the second key to the second device as the second device synchronizes its information with the user computer. In some embodiments, the user computer provides the information and the second key to the other device in the same protected format in which it received the information and the second key.
534 641
Before the information and keys are sent to the user, (1) the method receives in some embodiments a request from the user to receive some information, and (2) generates the first and second keys in the set of DRM computers. In some embodiments, the user has more than two devices for accessing the information. In some of these embodiments, the method in the set of DRM computers generates more than two keys for the user after receiving the user's request for the information. In such a case, each individual generated key is intended to enable the user to access the information on a particular device assigned to the user.
In some of these embodiments, the method also individually encrypts each generated key in a format used during its transport to its associated unit and during its storage and use in that unit. The transportation, storage, or use of any key in these embodiments does not require the decryption of another key generated by the set of DRM computers for other devices or data.
In some embodiments, the first device stores its encrypted keys for decrypting DRM data in a first Key Case, while the second device stores the encrypted keys for decrypting DRM data in a second Key Case. The first and second Keybags have the same format in some embodiments. Using Keybags with the same format minimizes the exposure of keys during data transfer and keys between the first and second devices as one of these devices synchronizes their data and keys with the other device. Exposure is minimized as it eliminates operations that result from transforming data between two different key case formats. In some embodiments, the first and second units encrypt their respective key bags, whereas in other embodiments they do not encrypt their respective key bags but only store individually encrypted keys in these key bags.
The set of DRM computers also transmits other DRM material together with the encryption keys in some embodiments. Such additional DRM data include, in some embodiments, data in relation to the DRM system, such as DRM type, rules, etc. The additional DRM material also includes in some embodiments encryption key data (for example, the type of key etc.). Other embodiments may include other types of DRM materials.
534 641
DESCRIPTION
The new features of the invention are set forth in the appended claims. However, for a more detailed explanation, a number of embodiments are written in the following figures.
Figure 1 shows an account-based DRM system according to some embodiments.
Figure 2 shows an example of a key case for transport for a user computer.
Figure 3 shows a transport key bag that includes all encryption keys that a device M can receive from the user computer during a synchronization operation.
Figure 4 shows that in some embodiments, the encryption key used to access a particular amount of data on a particular device is (1) generated and stored in the set of DRM servers, and (2) stored in the particular device.
Figure 5 conceptually illustrates a process that the set of DRM servers perform to process a request from a user account to purchase or purchase a license for a particular information.
Figure 6 conceptually illustrates a process that the set of DRM servers performs in some embodiments when it detects that a new device has been connected to a user account.
Figure 7 conceptually illustrates a process a user computer is performing when it needs to purchase or purchase a license for a particular information for a particular user account.
DETAILED DESCRIPTION OF THE INVENTION
In the following description, a number of details will be included to facilitate the explanation. However, those skilled in the art will recognize that the invention may be carried out without the use of these particular details. In other cases, well-known structures and units are shown in the form of block diagrams so as not to burden the description of the invention with unnecessary details.
I. OVERVIEW
Some embodiments provide a digital law management method (DRM) for the distribution of a data set to a user. The user has at least two devices
534 641 for accessing the information. The method sends the information to the user in a protected format. From the set of DRM computers, the method also sends to the user (1) a first key that allows the user to access the protected information on the first device, and (2) a second key that allows the user to access the protected information on the other device.
In some embodiments, the first and second keys are used to decrypt the information. In other embodiments, the first and second keys are used to decrypt an additional key or keys used to encrypt the information. In some embodiments, the method individually encrypts the first and second keys before sending them to the first and second units.
Additionally, in some embodiments, the first device is a user computer and the second device is another device (for example, a portable media player) that synchronizes its information with the user computer. In some of these embodiments, (1) the user computer receives the information and the first and second key and (2) then provides the received information and the second key to the second unit as the second unit synchronizes its information with the user computer. In some embodiments, the user computer provides the information and the second key to the other device in the same protected format in which it received the information and the second key.
Before the information and keys are sent to the user, (1) the method receives in some embodiments a request from the user to receive some information, and (2) generates the first and second keys in the set of DRM computers. In some embodiments, the user has more than two devices for accessing the information. In some of these embodiments, the method in the set of DRM computers generates more than two keys for the user after receiving the user's request for the information. In such a case, each individual generated key is intended to enable the user to access the information on a particular device assigned to the user.
In some of these embodiments, the method also individually encrypts each generated key in a format used during its transport to its associated unit and during its storage and use in that unit. The transportation, storage or use of any key in these embodiments does not require
534 641 decryption of another key generated by the set of DRM computers for other devices or data.
In some embodiments, the first device stores its encrypted keys for decrypting DRM data in a first key case, while the second device stores the encrypted keys for decrypting DRM data in a second key case. The first and second Keybags have the same format in some embodiments. Using Keybags with the same format minimizes the exposure of keys during data transfer and keys between the first and second devices as one of these devices synchronizes their data and keys with the other device. Exposure is minimized as it eliminates operations that result from transforming data between two different key case formats. In some embodiments, the first and second units encrypt their respective key bags, whereas in other embodiments they do not encrypt their respective key bags but only store individually encrypted keys in these key bags.
In some embodiments, the set of DRM computers transmits other DRM material along with the encryption keys. Such additional DRM data include in some embodiments data in relation to the DRM system, such as DRM type, rules, etc. The additional DRM material also includes in some embodiments encryption key data (for example, the type of key etc.). Other embodiments may include other types of DRM materials.
IL CONTOBASED DRM SYSTEM
Figure 1 shows an account-based DRM system 100 according to some embodiments. This DRM system distributes information in a way that ensures the legal use of the information. As shown in Figure 1, DRM system 100 includes a set of DRM servers 110 which distribute information to a number of units assigned to B user accounts. This figure shows two sets of units associated with two accounts, Account 1 and Account B. The set of units for account 1 includes a user computer 115 and a number of portable media players 130.1 The example shown in figure 1 is the units for the two different user accounts mutually exclusive. This need not be the case in some embodiments. Some embodiments may allow a device (for example, a user computer, etc.) to process DRM information for two different user accounts.
534 641
The set of DRM servers 110 connects to the user computers 115 and 120 via a computer network 125 such as a LAN, WAN, a network of networks (for example, the Internet), etc. Through this connection, the user computers 115 and 120 communicate with the set of DRM servers 110 to purchase, obtain a license for, update or otherwise receive information in certain embodiments. While in some embodiments, the set of DRM servers 110 sells or licenses information to the user computers, this set does not sell or license the information in other embodiments. In some embodiments, the set of DRM servers 110 only performs the distribution of information to authorized computers without any financial interest.
In some embodiments, the set of DRM servers 110 includes an information caching server that delivers encrypted information to a user computer 115 or 120 via the network 125 after another DRM server 110 determines that the computer 115 or 120 is entitled to the information. In some embodiments, the system 100 utilizes a number of caching servers to store information at various points in the network to increase the speed and efficiency of downloading information over the network.
As mentioned above, a user computer 115 or 120 assigned to a particular account communicates with the set of DRM servers 110 to purchase, license, update or otherwise receive information via the network 125 for that particular account. 1 some embodiments (1) provide the set of DRM servers 110 for each requested information in an encrypted format and (2) for each device associated with the request account provide an encryption key for decrypting the encrypted information.
Figure 1 shows an example where the set of DRM servers 110 distributes an encrypted amount of information (the information W) to the devices associated with the two different user accounts 1 and B. As shown in this figure, the set of DRM servers distributes the encrypted information W to both user computers 115 and 120 together with a set of encryption keys to access this information on each device associated with user accounts 1 and B.
534 641
The set of DRM servers distributes the information W and each set of encryption keys in an encrypted format. In addition, in some embodiments, each encryption key in the set is individually encrypted. The set of DRM servers 110 provides, in some embodiments, the set of encryption keys in a key bag for transport. A Key Bag is a storage structure that stores the encryption keys in a special format. The key bag for transport is encrypted in its entirety for transport in some embodiments, while it is not encrypted for transport in other embodiments.
Figure 2 shows an example of such a Key Bag for transport 205 for the user computer 120. As shown in this figure, the user computer 120 extracts each individually encrypted key from the Key Bag for transport 205 and stores these keys in a Key Bag 210 for storage. The keys in the Keychain 210 are the same as the keys in the Keychain 205 (that is, they are individually encrypted in the same format as in the Keychain 205). The key cases 205 and 210 are also fully encrypted in some embodiments, while not encrypted in other embodiments.
Figure 1 illustrates that each user computer 115 or 120 stores the received encrypted information W and the encryption key it receives for accessing this information. Each user computer 115 or 120 also provides each portable media player 130 with which it synchronizes with the received encrypted information W and the encryption key that the user computer received for the portable media unit.
For example, as shown in Figure 1, the user computer 115 provides the unit 2 for the account 1 with the received encrypted information W and the encryption key for accessing the encrypted information W on the unit 2. The user computer 120, on the other hand, provides the unit Z for the account B with the received encrypted information W and the encryption key for accessing the encrypted information W on the unit Z.
In some embodiments, each user computer deletes an encryption key as it provides another device after the synchronization operation, whereas in other embodiments, each user computer maintains the storage of the encryption keys as it provides devices that synchronize their information with the computer.
534 641 ίο
In some embodiments, each synchronizing unit stores the encryption keys it receives from its associated user computer in a Key Bag. Figure 3 shows an example of this for one of the units (unit M) associated with account B. This figure shows in particular a key bag for transport 305 which includes all encryption keys that a unit M can receive from the user computer 120 during a synchronization operation. As shown in this figure, the unit M extracts each individually encrypted key from the key bag for transport 305 and stores these keys in a key bag 310 for storage. The keys in the key bag 310 are the same as the keys in key bag 305 (that is, they are individually encrypted in the same format as in key bag 305). The key bags 305 and 310 are also fully encrypted in some embodiments, while not encrypted in other embodiments.
In some embodiments, the Key Case 205, 210, 305 and 310 all have the same format. The use of Key Bags of the same format minimizes key exposure during the transfer of encryption keys between the set of DRM servers, user computers, and the other devices associated with the accounts. Exposure is minimized because the use of the same format eliminates operations due to the transformation of data between two different formats for key bags. The individual encryption of each key also has the advantage that a device can decrypt and use any encrypted key for a particular information without decrypting an additional encryption key, which device does not need for that particular information.
Figure 4 shows that in some embodiments, the encryption key used to access a particular data set on a particular device is (1) generated and stored in the set of DRM servers, and (2) stored in the particular device. In particular, this figure shows a DRM architecture in which the set of DRM servers 110 generates and stores the encryption keys for each data set that this set distributes directly or indirectly to each device associated with each user account. This figure also shows that the user computers 115 and 120, which initially receive the DRM information for each account, store at least the encryption key for access to each set of information on the user computers. As mentioned above, in some embodiments, each user computer also stores the encryption key for accessing the received information on each device that synchronizes with the computer.
534 641
Figure 4 also shows that each unit stores the encryption keys for access to any amount of information to which access is granted. In some embodiments, some of the set of DRM servers generated encryption key for a particular device intended for encrypting a data set on that particular device. In other embodiments, any such key is intended to decrypt another key or keys used by the particular device to decrypt the information.
Figures 1 and 4 show user computers 115 and 120 receiving data and encryption keys from the set of DRM servers and synchronizing data and encryption keys with other devices associated with accounts 1 and B. One skilled in the art will recognize that some embodiments may have multiple devices (e.g., computers, portable electronic or communications devices, etc.) that directly receive information from the set of DRM servers 110 through a communication network. Those skilled in the art will also recognize that the user computer 115 or 120 may be included in any type of device, such as a consumer or commercial electronic device, a media center for home use, a hub, etc.
As mentioned above, in some embodiments, the set of DRM computers transmits another DRM matrial along with the encryption keys. Such additional DRM data include in some embodiments data in relation to the DRM system, such as DRM type, rules, etc. The additional DRM material also includes in some embodiments data concerning the encryption key (for example, the type of key, etc.). ). Other embodiments may include other types of DRM materials.
III. KEY GENERATION AND DISTRIBUTION FLOW
Figures 5-7 show conceptually a number of processes for generating keys and distributing data and keys in some embodiments. These processes are described in connection with the purchase or licensing of a particular set of information. Those skilled in the art will recognize that these processes can be performed without any of the financial goals or transactions of other embodiments.
Figure 5 conceptually illustrates a process 500 that the set of DRM servers performs to process a request from a user account to purchase or purchase a license prior to a particular information. The information can be any form of information, such as a music file, a video file, a document, a picture, etc. As shown in this figure
534 641, the process 500 starts when it receives (at 505) a request for the particular amount of data from a user computer that synchronizes all the keys and data for a particular user account.
The process then performs (at 510) a set of one or more operations to complete the purchase or license transaction. Thereafter, the process (at 515) identifies all the devices associated with the particular user account. At 520, the process generates an encryption key for each device associated with the particular user account. The encryption key for each particular device is the key that allows the particular device to access an encrypted version of that particular data set.
At 525, the process then stores each encryption key that it generated at 520. Then, at 530, the process individually encrypts each key it generated at 520. At 530, the process also stores the individually encrypted keys in a Key bag. In some embodiments, process 500 first performs the encryption operation at 530 and then performs the storage operation at 525. At 535, the process sends the key bag created at 530 to the user computer and then terminates. Together with the Key Case or the Key Case, the process in some embodiments (at 535) transmits another DRM matrial, as discussed above.
Figure 6 conceptually illustrates a process 600 that the set of DRM servers performs in some embodiments when it detects that a new device has been connected to a user account. As shown in this figure, the process starts 600 (at 605) when it detects that a new device is being added to a user account. The process can detect this when a new user account is initiated or it can detect this when a user computer tries to synchronize data with a new device.
At 610, the process determines whether a new device can be added to the user account. In some embodiments, this determination includes determining whether a maximum number of devices has already been connected to the user account. If the process determines (at 610) that the device cannot be added, the process is terminated without connecting the device to the user account.
Otherwise, the process (at 615) identifies all data previously purchased or licensed by the user account. For each previously purchased or licensed data set then generate
534 641 process (at 620) a key for a new device. The process then stores (at 625) each generated key. Thereafter, the process (at 630) individually encrypts each key as it generated at 620.1, in some embodiments, the process 600 first encrypts each key and then stores the encrypted keys (i.e., first performs the encryption operation at 630 and then performs the storage operation at 625).
At 630, the process then stores the individually encrypted keys in a Key bag for transport, which it then sends (at 635) to the user computer associated with the new device. Together with the Key Case or the Key Case, the process transmits in some embodiments (at 635) other DRM material, as discussed above. After 635, the process ends.
Figure 7 conceptually illustrates a process 700 that a user computer performs when it needs to purchase or purchase a license for a particular information for a particular user account. As shown in this figure, the process (at 705) starts when the user computer sends a request to the set of DRM servers to purchase or purchase a license for a particular data set for the particular user account. Then, at 710, the process performs one or more operations to complete the purchase or license transaction.
At 715, the process then receives the requested amount of data in an encrypted format plus a transport key bag containing an encryption key for each device associated with the particular user account and which can access the encrypted information. In some embodiments, the encryption keys are individually encrypted in the key bag for transport.
At 720, the process extracts the encryption keys from the Keychain for transport and stores these keys in a Keychain in the user computer. The key bag for transport and the key bag in the computer have the same format in some embodiments. The process also marks (at 720) a record it retains for each particular synchronization unit associated with the particular user account. This check mark was used to alert the user computer at the next synchronization with the particular device that the user computer needs to download newly received encrypted data and encryption key (s) to the particular device. After 720, the process ends.
534 641
IV. ENCRYPTION
As described above, several embodiments of the invention provide DRM processes and systems for distributing data. These processes and systems encrypt and decrypt data using encryption keys. Encryption of data involves transferring data from an interpretable form (called clear text) to a non-interpretable form (called cipher text) based on one or more encryption keys. Decryption of data involves transferring encrypted data to an interpretable form by using one or more encryption keys.
An encryption key is an information that controls the operation of an encryption algorithm. In symmetric encryption technology, the key used to encrypt data is the same as the key used to decrypt data. In asymmetric encryption technology, the same key is not used for encryption and decryption of data. In one method, for example, an encryption device utilizes a public key from a receiver to encrypt data and the receiver utilizes its private key to decrypt data.
Many of the characteristics of the embodiments described above can be implemented by a symmetric or asymmetric encryption method. In some embodiments, the encryption is also applied to a binary format of data. Although the unencrypted binary format for an amount of information can be difficult for a person to decipher, it can be deciphered by an application or operating system. On the other hand, an encrypted binary format for an amount of information should in principle not be decipherable with any application or operating system without first having been decrypted using one or more encryption keys.
Although the invention has been described with reference to a large number of specific details, those skilled in the art will recognize that the invention can be realized in other specific forms without thereby departing from the idea of the invention. For example, several embodiments described above portray the portable devices as devices that receive DRM information only through their synchronization with other user computers. However, those skilled in the art will recognize that in some embodiments, the portable players could access the DRM server (s) through a network to receive DRM information without interacting with another interconnected computer that can receive and access DRM data. Thus, one skilled in the art will recognize that the invention is not limited by the illustrative details described but should instead be defined by the appended claims.
534 641 /5
Contents12
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
23 members in 8 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 38148606 | United States of America | A | |
| 38148606 | United States of America | A | |
| 0950201 | Sweden | A | |
| 11381486 | – | – | – |
| SE20090050201 | – | – | – |
| US20060381486 | – | – | – |
Members23
| Document | Office | Kind | |
|---|---|---|---|
| EP1852799A2 | European Patent Office (EPO) | A2 | |
| US2007260548A1 | United States of America | A1 | |
| FR2902547A1 | France | A1 | |
| DE102007020775A1 | Germany | A1 | |
| WO2008048712A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2008048712A3 | World Intellectual Property Organization (WIPO) | A3 | |
| HK1110670A1 | Hong Kong, China | A1 | |
| CN101484902A | China | A | |
| SE531764C2 | Sweden | C2 | |
| SE0950201A1 | Sweden | A1 | |
| EP1852799A3 | European Patent Office (EPO) | A3 | |
| SE1150755A1 | Sweden | A1 | |
| SE534641C2This record | Sweden | C2 | |
| US8224751B2 | United States of America | B2 | |
| SE535644C2 | Sweden | C2 | |
| US2013003977A1 | United States of America | A1 | |
| CN101484902B | China | B | |
| DE102007020775B4 | Germany | B4 | |
| CN103455734A | China | A | |
| EP1852799B1 | European Patent Office (EPO) | B1 | |
| FR2902547B1 | France | B1 | |
| CN103455734B | China | B | |
| US10417392B2 | United States of America | B2 |
Numbers
- Publication, DOCDB
- 534641
- Publication, EPODOC
- SE534641
- Application
- 950201
- Application, DOCDB
- 0950201
- Application, EPODOC
- SE20090050201
Titles2
- Swedish
- Enhetsoberoende behandling av krypterad information
- English
- Device-independent processing of encrypted information
Classification
- CPC, 9
- H04L9/083
- G06F21/1012
- H04L9/08
- H04L9/14
- H04L2209/603
- G06F21/107
- G06F21/10
- H04L9/085
- Y10S705/901
- IPC, 2
- G06F21 10
- H04L9 08