Nova Patents
TW583568B

A secure access method and system

Abstract

A secure electronic content system and method is provided. The system includes a controller including an interface component, a host system coupled to the controller, the host system configured to present content under predetermined conditions, the host system operable with a navigation protocol, the host system further including a system manager operable with an associations component configured to be at least partially run by the host system, a translator configured to provide meanings and generate commands within the host system at least a first digital rights management (DRM) component configured to provide encoding and access rules for the content; and a file system component including a file system application programming interface (API) configured to provide a logical interface between a plurality of components.

TW583568B, drawing sheet 1
Sheet 1 of 502

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

176 claims: 139 independent, 37 dependent

  1. 1
    A secure electronic content system, comprising:a controller including an interface element;and a host system coupled to the controller, the host system being structured to present content under predetermined conditions, the host system The system can be operated using a navigation protocol. The host system further includes a system management device that can operate with the following components, including: a related component whose architecture is at least partially executed by the host system;a translation Server, whose structure is to provide meaning and generate commands within the host system;at least one first digital rights management (DRM) element, whose structure is to provide coding and access rules for the content;and a file system element, which includes a File system application programming interface (API), which is structured to provide a logical interface between multiple components. 1.一種安全電子內容系統,該系統包括:一控制器,其包括一界面元件;一主機系統,其耦接至該控制器,該主機系統係架構以在預定條件下呈現內容,該主機系統係可利用一導覽協定以進行操作,該主機系統更包括一系統管理裝置,其可利用下列元件以進行操作,包括:一關連元件,其架構以由該主機系統至少部分地執行;一轉譯器,其架構以提供意義及產生該主機系統內之命令;至少一第一數位權利管理(DRM)元件,其架構以提供該內容之編碼及存取規則;以及一檔案系統元件,其包括一檔案系統應用程式界面(API),其架構以在複數元件間提供一邏輯界面。 583568 六、申請專利範圍 1 ·—種安全電子内容系統,該系統包括: 控制器’其包括一界面元件; 主機系統,其耦接至該控制器,該主機 預定條件下呈現内$,該主機“係可以、構以在 進行操作,該主機系統更包括一系統管理 v二協定以 下列元件以進行操作,包括: ’八可利用 —關連元件,其架構以由該主機系統至少 :轉譯器’其架構以提供意義及產生該主機::執行; 令; 残系統内之命 至少一第一數位權利管理(DRM )元件,复加 内容之編碼及存取規則;以及 ”木構以提供該 檔案系統元件,其包括一檔案系統應用程 ,其架構以在複數元件間提供一邏輯界1 , I ^如申請專利範圍第lJS所述之系統 。去 可利用該主機系統及該控制器以進行/作匕括媒體,其 係以檔案持有該内容,其可經由該第 ^ y亥媒體 *件、該檔案系統元件、 _?利:理 (DRM )元件之至少一者以進行存取。第一數位權利管理 3·如申請專利範圍第丨項所述之 用該第一數位權利管理(Dr^ l、j ,、中,该内容係利 以及利用該第二數位用權^一理數管理(_)元件、 元件之一者以進行管理。 元件及忒檔案系統 第244頁 583568 六、申請專利範圍 4 ·如申晴專利範圍第3項所述之系統,其中, 權利官理(DRM )元件係經由一安全應用程^第一數位 以對—媒體上預先錄製内容之存取動作進面(API ) 5.如申請專利範圍第3項所述之系統,其 s 。 f利:理(DRM )元件係經由與該第—數位權^二數值 儿件關連之一安全應用程式界面(Ap “ Β理(DRM 體上預先錄製内容之存取動作進行管理。,精以對一媒 6·如申請專利範圍第i項所述之系統,i 係可利用—電腦系統以進行操作 主機δ亥主機系統 腦系統以避免該内容之存取動作。機糸統係利用該電 7如申請專利範圍第2項所述之系統, 利用該主機系統以進行操作、制'中n體係可 8.如申請專利範圍第丨項所述之系制器係二媒體碟片。 更包括一引擎亓杜 ' ^ ^、、、、 一中’该主機系統 法在該引擎外進Γ=兀件係包括預定元資料,其無 安全層。 丁子動作,該引擎係架構以提供一加密 9係=U ;範之系統’其中,該主機系統 引該引擎元件係包括預定元資料,其 71羊外進仃存取動作。 10· —種保全電子内容 界面-控制器以提供資料方之法於該方法包括: •接-主機系統輸:及輸出;以及 件下呈現内容,利用#盗,杀構該主機系統以在預定條 ^覽協定以操作該主機系統,在該 第245頁 583568 主機系統上操作一主機管理裝置 以: 1 亥主機系統係可操作 木構一關連元件以由該主機系統至少. 架構一轉譯器以提供意義、並產生該二地執仃, 架構至少一第一數位權利管理(DRI^幾系統内之命令; 之編碼及存取規則;以及 凡件以提供該内容 架構一檔案系統元件,其包括一檔案 (API),藉以在複數元件間提供—邏輯1 應用程式界面 如申請專利範圍第10項所述之方法饵审^二. 主機系統及該控制器以操作一媒體 。括’利用該 其r由該第一數位權:管 及第一数位核利管理(DRM、-件之至少一者以進行存取動作。 Μ )凡 1 2 ·如申請專利範圍第丨〇項所述之方法,复 利用該第一數位權利管理(DRM )元件及二 ==係 管理(DRM)元件、利用該第〆數位權利管理^drm位杻利 件、以及利用該第二數位權利管理(DRM )元件及該7 系統元件之一者以進行管理。 W虽案 1 3·如申請專利範圍第丨2項所述之方法,其中,該第一 位權利管理(DRM )元件係經由一安全應用程式界面 )以對一媒體上預先錄製内容之存取動作進行管理。 1 4·如申請專利範圍第丨2項所述之方法,其中,該第二數 位權利管理(DRM )元件係經由與該第一數位權利管理 (DRM )元件關連之一安全應用程式界面(API ),藉以對 第246頁 583568 六、申請專利範圍 一媒體上預先錄製内容之存取動作進行管理。 1 5 ·如申請專利範圍第丨〇項所述之方法,其中上 統係可利用一電腦系統以進行操作,該主、 違,主機系 電腦系統以避免該内容之存取動作。 糸、、先係利用該 1 6 ·如申請專利範圍第1 〇項所述之方法,兑 ^ 係可利用一電腦系統以進行操#,該控制器^亥控制器 主機系統以避免該内容之存取動作。 ’、,、可利用該 1 7·如申請專利範圍第丨〇項所述之方法,1 ^ 可利用該主德备於,、,、仓—4口价 〇 ^ 5亥媒體係 片。彡主機糸統^心作、且該控㈣係_媒體碟 1 8.如申請專利範圍第丨〇項所述之方法, 統更包括-引擎元件,該引擎元件係包括預中二,主機系 無法在該引擎外進行存取動作,該引擎::其 密安全層。 $朱構以 供一加 19.如申請專利範圍第1〇項所述之方法,i 統係可以耦接至一伺服琴,直配備 八 DX主機糸 機系統内之一引擎元:,:;整:楗供加密資料至該主 复h : 擎件,该引擎兀件係包括預定元資料, ......法在5亥引擎外進行存取動作。 一種们則一媒體碟片丨加密資料之未授權行動之方 内j媒,碟片係包括預先錄製内容之_第一部分及寫入 ^谷之一第二部分,該方法包括·· ::=體碟片上之一識別碼,纟中,該識別碼係包括至 ς :t:其係位於預先錄製内容之該第一部分、寫入内 奋之名第一部分、以及預先錄製内容之該第一部分及寫入 第247頁 583568 六、申請專利範圍 内容之該第二部分之一者; 决疋該識別碼是否包括一區段,其位於寫入内容一 部分; ^弟一 比車父該識別碼及至少一預定類型之識別喝,其中,一區尸 係位於寫入内容之該第二部分;以及 又 若該識別碼係該等至少一預定類型之識別碼之一者, 測一未授權行動。 、貞 21 ·如申請專利範圍第2 〇項所述之方法,其中,該媒體碟 片上該識別碼之讀取動作係位於一媒體碟片存取操作期、 ’其包括記錄、播放、取得播放金鍮、複製、開啟 、以 5 漆座命7 /Λγ -V S,丨、_ η 間 關 閉、以及產生動作之至少一者。 2 2.如申請專利範圍第21項所述之方法,其中,該媒體存 取碟片操作之功能係在偵測到該未授權行動後加以廢杜止子 23. 如申請專利範圍第20項所述之方法,其中,該識^ 片卞複數識別碼之一 各個識別碼係與該媒 及寫入内容之二者檔案關連,邊等檔案包括預先錄製内容 24. 如申請專利範圍第2〇項所述之方法,其中, 以ί3錄製内容之一識別碼,且該識別碼係有^於 寫入内合在該媒體碟片上之一位置。 、 25如申請專利範圍第2〇項所述之方法 片係-媒體碟#、一光碟、一數位影音 媒他體碟: 儲存媒體之一者。 畔及其他數位 26.如申請專利範圍第2〇項所述之方法,其中,該識別碼 第248頁 583568 ---- 六、申請專利範圍 ί預先錄製在該媒體碟片上,且該媒體碟片係、預先錄製 的〇 =·如申-睛專利範圍第20項所述之方法,其中,該預定類 ,糸二不寫入内容之一識別碼,且該識別碼係有關於該寫 2内谷在該媒體碟片上之一位置,其係該媒體碟片所獨一 無二的。 2 ·_如申胡專利範圍第2 0項所述之方法,其中,該識別碼 係一金鑰產生器之一種子,該金鑰產生器係由一金鑰盒子 擷取至少一金鑰,該等金鑰係用於一媒體碟片上之檔案解 除鎖定及解密動作之至少一者。 2 9 ·如申请專利範圍第2 0項所述之方法,其中,該識別碼 由二媒體碟片擷取並用於一弓丨擎中以進行一認證函數, / ι也函數係執行該識別碼及裏少一預定類型之識別碼之 比較動作、以及偵測一未授權行動。 3 Υ ·如申凊專利範圍第2 0項所述之方法,其中,一未授權 订動之該偵測動作係導致提供,失敗指示之該認證函數。 3 1 ·如申睛專利範圍第2 1項所述之方法,其中,一未授權 仃動之該偵測動作係導致該媒體碟片存取操作之功能廢 止。 3 j ·如申請專利範圍第2 〇項所述之方法,其中,偵測未授 權行動之该方法係發生在一媒體碟片’在一數位權利管理 協定下,利用一引擎進行存取時。 33·如申請專利範圍第2〇項所述之方法,其中,該識別碼 係位於一媒體碟片上,其可以耦接至一主機,該主機係一 讀取該I丨 讀取該言 該識別名 583568 六、申請專利範圍 ?丨擎、内嵌-弓丨擎之-裝I、一一 定、一開放計算環境中^ ^ 弟二者數位權利管理協 服器之一者。 w用私式、及一情報交換所我 34·:種偵測一媒體碟片上加 置,该媒體碟片係包括 、科之未授權行動之裝 :;之用-第二部分,該以:;内容之-第-部分及寫入 衣置,用以讀取該媒體磁一 碼係包括至少_ P p 識別碼,其中,該識別 分、寫入内容之=4;位内容之該第-部 :分及寫入内容之該第二u;先錄製内容之該第- 中若哕:二:t该識別碼及至少一預定類型之識別碼,其 區段,其位於寫入内容之該第二部 裝置,用了入内合之该第二部分之一區段係未授權;以及 ^ ^ α 以偵測一未授權行動,若該識別碼係該等至少一 預疋類型之識別碼之一者。 2 ·如申凊專利範圍第3 4項所述之裝置,更包括: 衣置’用以決定該識別碼是否為一預先錄製識別碼、或具 有預先錄製資料及寫入資料組合之一識別碼之一複製 3 6 ·如申凊專利範圍第3 4項所述之裝置,其中,讀取— 別碼之該裝置係包括一媒體碟片存取元件。 37·如申請專利範圍第34項所述之裝置,其中 別碼之該裝置係在一存取操作期間進行操作。 38·如申請專利範圍第34項所述之裝置,其中,該識另 係一媒體碟片上複數識別碼之一者,各個識別碼係與 第250頁 583568 --——. 申請專利範圍 體碟片上之至少 檔案關 速’該等檔案包括預先錄製内容 及寫入内容之一者。 … 39·如申請專利範圍第38項所述之裝置,其中,該等識別 碼之至少一者係該媒體碟片所獨一無二的。 40·如申請專利範圍第34項所述之裝置,其中,該識別碼 係一加密金鑰盒子之一種子,該金鑰產生器係利用該識別 碼以擷取至少一金鑰,藉以對一媒體碟片上之檔案進行解 除鎖定動作。 41 · 一種引擎,其架構以偵測一媒體碟片上加密資料之未 授權行動,該媒體碟片係包括預先錄製内容之一第一部分 及寫入内容之一第二部分,該引擎包括·· 一韌體元件,設置於一特殊用途積體電路(AS IC )上,該 韌體元件包括·· 一方塊,其係架構以讀取該媒體碟片上之一識別碼,其 中,該識別碼係包括至少一區段,其係位於預先錄製内容 之該第一部分、寫入内容之該第二部分、以及預先錄製内 容之該第一部分及寫入内容之該第一部分之一者; 一方塊,其係架構以比較該識別碼及至少一預定類型之識 別碼,其中若該識別碼包括一區段,其位於寫入内容之該 第二部分,位於寫入内容之該第二部分之一區段係未授 權;以及 -方塊’其係架構以彳貞測一未授權行動’若該識別碼係該 等至少一預定類型之識別碼之一者。 4 2. —種電腦程式產品,該電腦程式產品包括: 第251頁 583568 六、申請專利範圍 承載數位資訊之信號承載媒體,用以包括程式,該數位資 訊包括: 一方塊,其係架構以讀取該媒體碟片上之一識別碼,其 中,該識別碼係包括至少一區段,其係位於預先錄製内容 之該第一部分、寫入内容之該第二部分、以及預先錄製内 容之該第一部分及寫入内容之該第二部分之一者; 一方塊,其係架構以比較該識別碼及至少一預定類型之識 別碼,其中若該識別碼包括一區段,其位於寫入内容之該 第二部分,位於寫入内容之該第二部分之一區段係未授 權;以及 一方塊,其係架構以偵測一未授權行動,若該識別碼係該 等至少一預定類型之識別碼之一者。 4 3 · 一種識別一位置之方法,該位置於與一媒體碟月之一 製造商關連,該媒體碟片係持有内容,該方法包括: 提供該媒體碟片,之指令; 在該媒體碟片根據該等指令以安裝至一主機期間,安裝一 識別碼於該媒體碟片上,該識別碼係包括與該製造商關連 之一程式碼;以及 待傳輪資料至一伺服器後,讀取該識別碼以找到與該製造 商關連之一位置,該位置係關連於該媒體磘片之該製造商 且獨立於與該媒體碟片沒有關連之任何製造商。 44·如申請專利範圍第43項所述之方法,其中,該媒體碟 片之該等指令係包括:識別購買該媒體碟片之一製造商。 4 5 ·如申請專利範圍第4 3項所述之方法,其中,購買該媒 第252頁 583568 六、申請專利範圍 體碟片之該製造商之該識別動作係包括:在該等指令中提 供一程式碼、一全球資源定位器(URL )、與該製造商關 連之一加密金鑰、及與該製造商關連之一加密金鑰之一部 分之一者。 4 6. —種識別一位置之系統,該位置於與一媒體碟片之一 製造商關連,該媒體碟片係持有内容,該系統包括: 該媒體碟片之指令;以及 一軟體安裝元件,其關連於該媒體碟片,該軟體安裝元件 係可在該媒體碟片根據該等指令安裝至一主機期間舉例說 明,該軟體安裝元件係可操作以安裝該媒體碟片上之一識 別碼,該識別碼係包括與該製造商關連之一程式碼,該識 別碼關連該製造商之一位置,藉以使該主機及一伺服器間 之一連接可操作以開啟該位置。 4 7.如申請專利範圍第4 6項所述之系統,其中,該媒體碟 片之該等指令係包括:識別購買該媒體碟片之一製造商。 4 8.如申請專利範圍第46項所述之系統,其中,購買該媒 體碟片之該製造商之該識別動作係包括:在該等指令中提 供一程式碼、一全球資源定位器(URL )、與該製造商關 連之一加密金錄、及與該製造商關連之一加密金錄之一部 分之一者。 49.如申請專利範圍第46項所述之系統,其中,該位置係 一網際網路位置,其包括網頁以對該媒體碟片上的儲存内 容進行解除鎖定動作,該網際網路位置更提供選擇性供 應,藉以讓該製造商能夠在網際網路上購買。 第253頁 583568 5 〇 ·如、申请專利範圍第4 6項戶斤述之系統’其中,該主機係 一引擎、内嵌一引擎之一裝置、一第三者數位權利管理協 疋以及一開放計算環境中執行之一應用程式之一者。 5 1 · —種經由一媒體碟片識別_位置之方法,該媒體碟片係 包括至少一可寫入部分及一不玎重寫部分,該方法包括: 將該位置寫入該可寫入部分; 散佈至少一媒體碟片給至少〆實體,該位置係關連該等媒 體碟片至該等實體;以及 、 若發生該等媒體碟片之一返卸,則根據預定條件以改變該 位置。 52·如申請專利範圍第51項所述之方法,其中,該位置係一 全球資源定位器(URL ),且其中,該等預定條件係包括: 決定該等實體之一市場佔有率。 5 3·如申請專利範圍第51項所述之方法,其中,該位置之改 變動作係由一内容提供者執行,該内容提供者係接收該等 媒體碟片,包括至少一媒體碟片、以及在該改變動作後將 該等返回媒體碟片散佈至該等實體之相同或不同實體。’ 54·如申請專利範圍第53項所述之方法,其中,該散佈動作 係根據該等媒體碟片之一租賃合約,該租賃合約係同咅未 售出媒體碟片之返回。 5 5· —^種識別一位置之系統,該糸統係包括· 一媒體碟片,其具有至少一可寫入部分及一不可重寫部八 該媒體碟片係將該位置寫入該玎寫入部分; …刀’ 散佈至少一媒體碟片給至少〆實體,該位置係關連該等媒 第254頁 583568 六、申請專利範圍 ----— 體碟片至該等實體;以及 若該4媒體碟片之一返回發生日守’則根據預定條件以微 該位置。 ’、 艾 5 6 ·如申請專利範圍第5 5項所述之系統,其中,該媒體碟片 係一媒體碟片、一光碟、/數位影音光碟、及其他數位 存媒體之一者。 _ 57·如申請專利範圍第55項所述之系統,其中,一識別竭係 預先錄製於該媒體碟片上,且該媒體碟片係預先錄製的’今 識別碼係提供到該位置之/連結。 ’ μ 5 8 · —種電腦程式產品,該電腦程式產品係包括: 信號承載媒體,其具有程式,用以·· 在該信號承載媒體根據指令安裝至一主機期間做為範 以及 ^ 安裝一識別碼至該信號承載媒體上,該識別碼係包括與該 信號承載媒體上隱藏内容之一製造商關連之一裎式碼,該 識別碼係關連於該製造商之一位置,藉以使該主機及二^ 服器間之一連接可操作以開啟該位置。 59· 一種改變一儲存媒體上保全資料之方法,該方法包括· 與一主機建立一安全對話; 匕括· 接收,經由通信通道,對該保全資料進行解除鎖定之一命 令二其係由至少一内容儲存模型進行管理;以及 =Τ王二料進订解除鎖定,其中,該命令係回應於該媒體 ’、 之〒令,該識別碼係架構以管理該保全資料之存 取動作,且至少一内容儲存模型係一安全内容管理裝置。 第255頁 583568 六、申請專利範圍 立一安全對話係包括:經由 通k通道以鏗別該主機 述之方法,其中,與一主機建 6 0 ·如申請專利範圍第5 9項所述之方法,其中,與一主機建 ”〜 叫、〇伯 · ^ CW 6 1 ·如申請專利範圍第5 9項所 立一安全對話係包括:傳輸鑑別資料至該主機。 62·如申請專利範圍第59項所述之方法,更包括:由該主機 接收一指示,藉以表示欲解除鎖定之内容。 6 3 ·如申請專利範圍第5 9項所述之方法,更包括:決定欲解 除鎖疋之内容係透過掃描一目錄結構及注意安全資料以達 到。 64·如申請專利範圍第59項所述之方法,其中,該安全内容 管理裝置係一數位權利管理協定。 65·如申請專利範圍第59項所述之方法,其中,該等内容儲 存模型係包括至少二數位權利管理協定。 66·如申请專利範圍第59項所述之方法,其中,該安 管理裝置係一專有及一第三者數位權利管理協定之一者。 67·如申請專利範圍第59項所述之方法,其 取動作係由_稽案系統進行管理。 1枓之存 6:之:Λ架ί以對一儲存媒體上安全資料進行解除鎖定動 作之糸統,该系統係包括: 郭 =内容儲存模型,用於該儲存媒體上儲存之保全資料; 上係能夠對保全資料進行解除鎖定動作,其中兮 料推二=正5亥儲存媒體上該資料之屬性,藉以依攄f+兮二 枓進仃解除鎖定動作 令,根 =該貢 分㈣#槟型以對 第256頁 583568 六、申請專利範圍 该保全資料進行解除鎖定動作。 69·如申請專利範圍第68項所述之系統,其中,該弓丨擎係 收該命令以對一訊息中之該資料進行解除鎖定動作,复 邊Λ息係經由一通信通道接收。 ’ 70·如申請專利範圍第69項所述之系統,其中,該通 係一網際網路通道、一衛星通信通道、一無線 。 逼 有線通道之一者。 、及一 71•如申請專利範圍第69項所述之系統,其中,該 密的。 u W係加 72·如申請專利範圍第“項所述之系統,其中,誃 存模型係包括至少二數位權利管理協定。, 内容儲 73·如申睛專利範圍第68項所述之系統,其 模型係一專有及—第三者數位權利管理協定之^一内各儲存 74·如申睛專利範圍第68項所述之系統,其中今次丄 取動作係由—檔案系統進行管理。 …亥貝料之存 7 5 · —種電腦程式產品,其包括: 一儲存媒體; 複數内容儲存模型,用於該儲存媒體上 ::腦裎式,該電腦程式係包括: 存之貝料; 扎、7,其係調整該儲存媒體上該資料之屬性 二a内甘各儲存模型之保全資料進行解除鎖定^朴餅根據至 # a,=係經由一通信通道與一主機進行通作·、’ 曰々,/、係由該主機接收一命令,藉以對 °,以及 除鎖定動作。 對該保全資料進行解 第257頁 Όδ 、申請專彳愧1| , γ 0 士 通·作D申請專利範圍第75項所述之電腦程式產品,其中,該 。、逼係一網際網路通道、一衛星通信通道、一無線通 g、及—有線通道之一者。 專利範圍第75項所述之電腦程式產品,其中,該 伴八一’更包括:指令,其係藉著追蹤一目錄結構及識別 王育料 藉以決定欲解除鎖定之資料。 雷日《如^申〇^專利範圍第75項所述之電腦程式產品,其中,該 70 更包括:指令,用以與該主機建立一安全對話。 雷申4請專利範圍第75項所述之電腦程式產品,其中,該 铛1更包括:指令,用以解密對該安全資料進行解除 鎖疋動作之該命令。 H申利範圍第75項所述之電腦程式產品,其中,該 谷:子模型係包括至少二數位權利管理協定。 81 ·如申凊專利範圍第7 5項所述之電腦程式產品,其中至 =::容儲存模型係_專有及一第三者數位權利管理協定 ΐ.置'係種包對括'儲存媒體上安全資料進行解除鎖定之裝置,該 裝置,用以與一主機建立一安全對話; i: ’二接收乂經由一通信通道,對該保全資料進行解除 鎖疋動作之一命今盆由姑瓜入— 于 模型進行管理;:,及貧料係由至少-内容館存 ΐ ϊ ’二二對儲存媒體上該保全資料進行解除鎖定動作 ,、中’該中令係回應於該媒體上之—識別碼,該識別碼係架 II 第258頁 583568 六、申請專利範圍 ::以::該保全資料之存取動作,且至少一内容 係一女全内容管理裝置。 hi 83種鑑別一裝置之方法,該方法係包括: 由該裝置接收-憑證,該憑證係包括複數攔位,其 位以持有一憑證管理中心之一數位簽章; 索 確^ A心也中之该專數位簽章,該確認動作係至少包括: 利用孩憑證管理中心之公開金鑰以確認該憑證 數位簽章;以及 Y 之 利用一裝置之公開金鑰以確認一裝置之數位簽章; 由^來源接收認證資料,該認證資料係根據預定條件以識 別該憑證中之至少一資料為有效或無效的;以及 w 若該等數位簽章確認為有效的,則傳輸一對話金鑰至該袭 置,藉以建立一安全通信通道。 、 8 4 ·如申請專利範圍第8 3項所述之方法,其中,該來源係一 可攜式媒體及勃體之一者。 8 5 ·如申請專利範圍第8 3項所述之方法,其中,該裝置係一 引擎、内嵌一引擎之一裝置、,第三者數位權利管理協 定、一開放計算環境中執行之/應用程式、及一情報交換 所伺服器之一者,該憑證係用以識別至少一安全應用程式 界面(AP I ),藉此,可利用該装置以進行操作之一應用程 式係可以進行存取動作。 86·如申請專利範圍第83項所述之方法,其中,該憑證係由 根據一裝置類別指派之一私密金輪進行數位簽章,該裝置 類別係包括··引擎、内嵌〆弓丨擎,不具外部數位I /〇埠之 583568 六、申請專利範圍 裝置、内嵌一引擎、具有ί/O埠之裝置、未内嵌一引擎之 裝置應用程式、第三者數位權利管理協定、及情報交換所 伺服器。 87·如申請專利範圍第83項所述之方法,其中,該裝置之憑 證動作係包括:憑證連接一主機於第二主機安全' 通信通道 之一第二主機,該憑證動作係同意該主機及該第二主機間 之一複製函數。 88·如申請專利範圍第83項所述之方法,其中 ^資料係用來指定該裝置之一產品類別、_’產品一模 型、一修訂、一序號之至少一者。 次%^ /申明專利範圍第8 8項所述之方法’其中,該來源認證 斗係與該憑證中之該資料比較,藉以將該裝置之該產品 j別、該產品線、該模型、該修訂、及該序號之至一 識別為無效的。 如申請專利範圍第83項所述之方法,其中,該憑證係包 、一憑證管理中心識別碼攔位、一版本攔位、一簽章金鑛 馬攔位、一曝露方法攔位、一公司攔位、一模型識別 簽j位、一修訂欄位、一元資料識別碼攔位、一裝置數位 仇早金鑰欄位、一憑證管理中心數位簽章欄位、一序號搁 〜,一協定公開金鑰攔位、及一裝置數位簽章欄位之至少 少〜,其中,該憑證管理中心數位簽章係確認該憑證中之至 ^〜攔位,且該裝置數位簽章係確認該憑證中之至少一搁 如申請專利範圍第83項所述之方法,其中,該憑證管理 583568 六、申請專利範圍 中心係讓一實體接收該憑證,旅透過無效錯誤或具有潛在 缺陷的裝置,藉以控制該裝置之品質。 9 2 ·如申請專利範圍第8 8項所述之方法,其中,該憑證更包 ,一裝置製造商提供之攔位,包括該公司公開金鑰,其中, ^公司公開金鑰係由該憑證管理中心數位簽章。 =·如申請專利範圍第88項所述之方法,其中,該憑證更包 修—裝置製造商提供之攔位,該等攔位包括該裝置公開金 9阳,其中,该裝置公開金錄係由該公司數位簽章。 =·如申請專利範圍第88項所述之方法,其中,該裝置之該 一 ^類別、該產品線、該模塑、該修訂、及該序號之至;置。係,在該裝置傳送一認證程序後,提供給一憑證產生^ 9^·如申請專利範圍第83項所述之方法,其中,該憑證 ^ =少一憑證類別,該等憑證類別係提供一組方=°复可θ 在傳輪該對話金鍮後加以揭露。 方法’其可以 •如申請專利範圍第95項所述之方法 二括數位權利管理(刚)方法,其包括二:,二方法係 ,元資料方法、及—解除鎖定方法: = 寫入安 利管理⑽)方法係可根據該裝置,一類者型 97如申請專利範圍第96項所述之方法i 該=3::;!、關連於一情報交換所飼服器; 1方法係關連於L及可利用—第二數位 第26〗頁 583568 理(DRM )應用程式以進行操作之一第一數位權利管理 (DRM)應用程式之一者;以及 ,記錄方法係關連於一播放器、一原版影片製作工具、-貝訊站、及一情報交換所伺服器之至少一者。 98·如申請專利範圍第83項所述之方法,其中,各個攔位 持有163位元橢圓曲線加密之326位元數位。 ’、 99·如申請專利範圍第83項所述之方法,其中,該憑證其 中心公開金鑰係參照該憑證之一攔位。 兄吕 100·如申請專利範圍第83項所述之方法,其中 中心公開金鑰係位於該韌體元件。 该憑證管理 101· —種憑證一裝置之裝置,該裝置包括: 包括複 至少包 裝置,其係由該裝置接收一憑證要求,該憑證要 數欄位,包括持有一協定公開金鑰之一攔位; π 裝置,用以確認該憑證中之數位簽章,該確認動作係 利用該憑證管理 簽章;以及 中Q Α開金錄以確認該憑證管理中心數位 利用該憑證中之一裝置公開金鑰以確認 裝置,其係由一來源接收認批次 I位簽早; 條件以識別該憑證中之至;:一資料:::二:係根據預定 裝置,其係傳輸一對話金鑰至該〜枓為的;以及 通道,當該等數位簽章係確認為有 的。 安全通信 102· —種引擎,其架構以馮供:又的 ^ 一韌體元件,包括: 心a 機,該引擎係包括·· ^3568 六、申請專利範圍 二方塊,其架構以由該主機接收一憑證,該憑證係包括 攔位,包括持有一協定公開金鑰之一攔位; :=塊’其係架構以確認該憑證中之至少一數位簽章,其 ^包括: 、 =用-憑證管理中心公開金鑰之一憑證管理中心數位 早;以及 H'中一裝置公開金餘之一裝置數位簽章,·以及 奸姑塊,其係架構以由一來源接收認證資料,該認證資料係 ^據預定條件以識別該憑證中之至少料為有效或無= 的,以及 一方塊,其係架構以傳輸一對話金鑰至該裝置,藉以建立一 安全通信通道,#該等數位簽章係相為有效:。建 10 3. —種電腦程式產品,該電腦程式產品係包括: 承載數位資訊之信號承载媒體,其持有一韌體元件,該韌體 元件係包括: 一方塊,其係架構以由該裝置接收一憑證,該憑證係包括複 數欄位,包括持有一協定公開金錄之一攔位; 一方塊,其係架構以確認該憑證中之數位簽章,其至少包 括: Φ 利用該憑證管理中心公開金鑰之一憑證管理中心數位簽 章;以及 利用δ玄憑證中一裝置公開金餘之一裝置數位簽章;以及 一方塊,其係架構以由來源接收認證資料,該認證資料係 根據預定條件以識別該憑證中之至少一資料為有效或無效 583568 的;以及 一方塊,其係架構以傳一 二通=,當該等數位❺ 該憑♦項:述之電腦程式產品,其中, in, ^ ^ τ A開金錄係參照該憑證之一欄位。 該憑項所述之電腦程式產品,其中, 甲 A開金鑰係位於該韌體元件。 # 二一種廢止一裝置之方法,該方法係包括: γ裝置接收一憑證,該憑證係包括至少一 至少一攔位持有一簽章; 嘗試確認該簽章; ^來源接收-廢止表列,該廢止表列係 至二-貢料為有效或無效的,該資料係包括該憑 J 一攔位;以及 〜 少 一資料係確 該對話金鑰 f至少一簽章中有一簽章無法成功識別且至少 為無效的,則避免傳輸一對話金鑰至該裝置, 係建立一安全通信通道所必須。 , 之方法,其中,該廢止表 之方法,其中,該廢止表 1 0 7 ·如申請專利範圍第1 〇 6項所述 列係在檔案存取時加以評量。 1 〇 8 ·如申請專利範圍第丨〇 7項所述 列係在檔案產生時加以儲存。 109·如申請專利範圍第1〇6項所述之方法,其中,各個禾 係具有一廢止表列,並且,具有複數廢止表列之複1 具有重覆項目。 ^ 11屯如申請專利範圍第106項所述之方法,其中,該廢止表 列係伴隨該檔案以儲存於媒體。 11 5 ·如申請專利範圍第丨〇 6項所述之方法,其中,該廢止表 列係複製至各個裝置。 11 如申請專利範圍第1 0 6項所述之方法,其中,該廢止表 列係^ 一飼服器維護,藉以使與〆伺服器進行通信之内容 表現裝置能夠接收直接傳送至該裝置之更新廢止表列。 117·如申請專利範圍第1〇6項所述之方法,其中,複數廢止 表列係基於逐一檔案以儲存於媒體上,藉以使該媒體上之 583568 申請專利範圍 至少一槽案能夠具有與該槽案關連之一廢止表列。 11 8 ·如申請專利範圍第1丨7頊所述之方法,其中,該廢止表 列係在一檔案存取程序、以及/鑑別及一檔案存取程序之 一組合期間進行存取動作。 11 9 ·如申請專利範圍第丨〇 6項所述之方法,其中,該廢止表 列係包括一毒藥以避免一内容表現裝置進行操作。 120·如申請專利範圍第106項所述之方法,其中,該廢止表 列係在該内容表現裝置連接至一彳司服器時進行更新。 1 21 ·如申請專利範圍第丨〇 6項所述之方法,其中,一内容表 現裝置之廢止動作係至少包括:至少一公開金錄之廢止動 作,其中,一公開金餘之廢止動作係廢止任何對應之簽章。 1 2 2 ·如申請專利範圍第1 0 6項所述之方法,其中,該廢止表 列係利用一獨特處置以維護成該媒體上該檔案系統内之一 物件。 123·如申請專利範圍第106項所述之方法,其中,該廢止資 訊係集中放置。 、 124·如申請專利範圍第106項所述之方法,其中,該來源係 一可攜式媒體及韌體之一者。 、 125·如申請專利範圍第1〇6項所述之方法,其中,與憑證及 /或公開金鑰是否已經廢止相關之該資訊係戳印於該媒 體。 ’、 126·如申請專利範圍第1〇6項所述之方法,其中,該裝置係 一引擎、内嵌一引擎之一元件、一第三者數位權利管理協 定、一開放計算環境中執行之一應用程式、及一情報交換 第266頁 六、申請專利範圍 斤伺服器之 4API),藉 i以進行存 127 , •如申請 才艮據〜裝置 包括:引擎 内嵌〜擎且 :應用裎式 後如申請 ;讀:料係129 4 Ϊ訂次•如申請 貝料係與該 ΐ別、該產 广別為無效 3〇.如申請 ^括下列攔 馬、版本、 輪識別碼、 識別碼、主 協定金鑰、 一者,該憑證係識別至少一安全應用程式界面 此,可利用該裝置以進行操作之一應用程式係 取動作。 專利範圍第1 06項所述之方法,其中,該憑證係 類別指派之一私密金錄以簽章,該裝置類別係 、内嵌一引擎且沒有外部數位I /〇埠之元件、 具有數位I /〇埠之元件、及未内喪一引擎之主 專利範 指定該 、及一 專利範 憑證中 品線、 的。 專利範 位之至 憑證管 曝露方 機簽章 及主機 圍第106項所述之方法,其中,該憑證中 裝置之一產品類別、一產品線 模 該憑證中之至少 至少一搁位。 1 3 1 ·如申請 序號之至少一者 圍第128項所述之方法,其中,來源認證 之該資料比較,藉以將該裝置之該產品 該模型、該修訂、及該序號之至少一者 圍第129項所述之方法,其中,該憑證係 少一者,其包括:憑證管理中心識別 理中心公開金鑰、憑證管理中心公開金 法、公司、模型識別碼、修訂、元資料 公開金鑰、憑證管理中心簽章、序號、 簽章,其中,該憑證管理中心簽章係確認 欄位,且該主機簽章係確認該憑證中之 專利範圍第106項所述之方法,其中,該憑證係 第267頁 ^3568 六 '申請專利範圍 - 只體月匕夠接收該憑證,並葬装么 . 陷之ρg者無效錯誤或具有、、既力处 衣置以控制該裝置之品質。 日在缺 L如申請專利範圍第13〇項所述之 中:裝置製造商提供之欄位,包括該裝 金:'更 13, Μ衣置公開金鑰係由一私密金鑰簽章。 '’鑰,- *如申請專利範圍第丨3〇項所 该產品_如分* ^ ^ ^万汝,其中,該主機之 少-者係/、:產品線、該模型、該修訂、及該序號之至 裂置。係,在該主機傳送—認證程序後,傳送至—憑證產生 1 3 4 指C!!i圍第106項所述之方法,其中,該憑證係 c輪該對話金鑰後加以揭露。 方法,其可 ,申請專利範圍第丨%項所述之方 係包括數位權利管,,、干…亥組方法 方法寫入安全元資料、及解除鎖定,且該等 1 3 β 了根據該裝置之一類型以進行操作。 該解::利範圍第13 5項所述,方法,其中, 古亥、I制、疋方法係關連於一情報父換所伺服器; 理(c係關連於-引擎、及可利用-第二數位權利管 (DRM、 應用程式以進行操作之一第—數位權利管理 )應用程式之一者;以及 ΐ ^入方法係關連於一播放器、一原版影片製作工具、一 7°站、及一情報交換所伺服器之至少一者。 •如申請專利範圍第1〇6項所述之方法,其中,各個欄位 583568 六、申請專利範圍 係持有1 6 3位元橢圓曲線加密之3 2 6位元數值。 138· —種廢止一主機之裝置,該裝置係包括: 裝置,其係由一主機接收一憑證,該憑證係包括複數攔位, 包括持有一憑證管理中心簽章之一協定公開金錄之一攔 位; 裝置,用以確認該憑證上之簽章,該確認動作係包括: 利用該協定公開金鑰以確認該憑證管理中心簽章;以及 利用該憑證上之一主機公開金鑰以確認一主機簽章; 裝置,其係由一來源接收認證資料,該認證資料係根據一廢 止表列以識別該憑證上之至少一^資料為有效或無效的;以 及 裝置,其係避免傳輸一對話金鑰至該主機以建立一安全通 信通道,若該等簽章係無效的。 1 3 9 · —種引擎,其係架構以廢止一主機,該引擎係包括: 一方塊,其係架構以由一主機接收一憑證,該憑證係包括複 數欄位,包括持有一憑證管理中心簽章之一協定公開金錄 之一棚位; 一方塊,其係架構以確認該憑證上之簽章,該確認動作係包 括·· 利用該協定公開金鑰以確認該憑證管理中心簽章;以及 利用該憑證上之一主機公開金鑰以確認一主機簽章; 一方塊,其係架構以由一來源接收認證資料,該認證資料係 根據一廢止表列以識別該憑證上之至少一資料為有效或無 效的;以及 第269頁 583568 六、申請專利範圍 一方塊,其係架構以避免傳輸一對話金鑰至該主機以 一安全通信通道,若該等簽章係無效的。 建立 WO· —種電腦程式產品,該電腦程式產品係包括: 承載數位資訊之信號承載媒體,其可利用一動體以 作,該數位資訊係包括程式,其包括: — 行操 方塊,其係架構以由一主機接收一憑證,該憑證係勺 數攔位,包括持有一憑證管理中心簽章之一協匕括複 之一攔位; 疋a開金輪 之簽章,該確認動作係勺 一方塊,其係架構以確認該憑證上 括: 利用該協定公開金鑰以確認該憑證管理中心立、 =用该憑證上之一主機公開金鑰以確認一主機簽章^ 係主架構Λ由一來源接收認證資料,該認證資料々 效的;以及 貝枓為有效或為 方塊,其係架構以避免傳 ^ JuL 1安全通信通道,若該等簽章係無效的。 蔣1向二種巧全媒體上儲存資料之方法,該方法包括: 之存取動作;以及 %係管理複數等級 體以根據該等内容特權及預定條件同意該内容之 ^等第141項所述之方法,其中,該内容之 $寻?及之存取動作之_ 5 至夕包括播放、複製、及處理該 第270頁 583568 六、申請專利範圍 内容之一者。 143·如申請專利範圍第142項所述之方法, ^ =包括複製一有限數目、或一無限數目之、員定;f製 円谷複製。 1曰請專利範圍第143項所述之方法,其中,該無限數 目之複衣係有關於該内容之一原始來源複製、 原始來源複製之一複製。 145·如申請專利範圍第141項所述之方法 條件係至少包括: ,/、甲,4寺預疋 鑑別一通道以進行該内容之傳送;以及 :ί :ΐΐ表二以’在同意存取前,得到一廢止指標,其中 該尾止h ^之存在係用來排除允許存取。 , 1^6如申睛專利範圍第141項所述之方法, 係可利用-資料管理系統以進行操作:其ΐ附: 谷係儲存於該媒體上該管理; 八,該内 作。 版上,3 理糸統係官理戎内容之存取動 -^ ^ 控制态中之韌體,該韌體係至少' , 匕全中應用程式界面(API)及一開放應用程式心 用程式界面(API) 統賁料進行存取動作;以及 插案系 =全應用又式界面(AP 係根據該媒體上之至少一 ',精以同思對该媒體上之保全資料進行存取動作。識 583568 六、申請專利範圍 明專利範圍第147項所述之方法,其中,該安全應 王工丨、面(ΑΡί )係包括一第一安全應用程式界面(API ^至乂 一額外安全應用程式界面(API ),該第一安全應 】t H面、(AP 1)係可利用至少一該額外安全應用程式 ^ 以進行操作,該至少一額外安全應用程式界面 係提供外加保全層,該第一安全應用程式界面 API )係利用該等外加保全層以控制該内容之存取動 作。 1勺範圍第147項所述之方法,,中,該章刃體係 匕括在特殊應用積體電路(ASIC)中。 150:如申請專利範圍第146項所述之方法,其中,該資 理糸統係經由至少一應用程式界面(Αρι )以管理内容 = 程式界面UPI)係利用—主機以限制㈣ 151.如申請專利範圍第15〇項所述之方法,其中誃 式界面(AP I )係能夠避免該内容之方塊等級存^ 了壬 152·如申請專利範圍第15〇項所述之方法,其子 式界面(AP I )係僅能夠經由一鑑別通道以進二=w用程 作。 延仃存取動 153·如申請專利範圍第14ι項所述之方法 一可攜式媒體,包括一光學碟片,且該内容;j系勺,以媒體係 製㈣容、記錄…複製内容、解除鎖定:;容原 定内容之至少一者。 合及解除 154·如申請專利範圍第147項所述之方法复 ’,、丫,涊識別m 583568 六、申請專利範圍 係提供一金 盒子之一種子,該金餘盒子係提供解除鎖定 内容及解密内容之至少一者之金餘。 155·如申請專利範圍第154項所述之方法,其中,該媒體係 持有原版影片製作内容及記錄内容之至少一者,該原版影 片製作内容及該記錄内容分別關連於一金鑰盒子,且該金 錄盒子係連結於該媒體。 156.如申請專利範圍第155項所述之方法,其中,該原版影 片製作内容及該記錄内容,伴隨其關連金鑰盒子,係分別提 供一完整存取系統。 15 7·如申請專利範圍第155項所述之方法,其中,該金输盒 子可以與一第一媒體解除連結、並重新連結至一第二媒 體,藉以在該苐二媒體上產生一完整存取系統,其同.鱼' 以該金鑰盒子。 158· —種保全媒體上儲存内容之裝置,該裝置包括: ^少二工具,用以傳輸内容至該媒體,該工具係架構以附 複數等級之存取動作,其中,内容特權及預定條件係理 内容之存取動作。 μ s该 1 5 9 ·如申請專利範園第1 5 8項所述之裝置,更包括: 一密碼鎖,其耦接至該工具,該密碼鎖係架構以將一金 子連結至該媒體。 ’ ” ^孟 160·如申請專利範圍第159項所述之裝置,更包括: :特殊應用積體電路(ASIC ),其耦接至該密碼鎖;以及 I隨機金鑰產生器,其内嵌以該特殊應用積體電路(MW ,忒隨機金鑰產生器係至少提供該媒體之一秘密金輸。 583568 六、申請專利範圍 162^巾請專利範圍第161二述處之理心G -内者容複製 包括 复製-限定數目之特定内容複製。 :件範圍第158項所述之裝置,其中,該等預定 進行該内容之傳送動作;以及 松·一 廢止表列以 ά· Γ51音:vc, 皮中^ t ^ ,,在门心存取動作前,取得一廢土扣柄, ^^曰不之存在係用來排除允許存取動作。 利範圍第158項所述之裝置,#中,㉟等附加 利用一資料管理裂置以進行操作,其中,該内 貝料儲存於該媒體上,該管理系統係經由該特 殊=積體電路(ASIC)上之物體以管理該方塊資料,藉 以避免該韌體外之内容存取動作。 165·如申請專利範圍第164項所述之裝置,其中,該特殊應 用積體電路(ASIC )係放置於一控制器中,該特殊應用積 體電路(ASIC)上之該韌體係至少包括一安全應用程式界 面(API )及一開放應用程式界面(Αρι ),其中: 該開放應用程式界面(API )係同意該媒體上檔案系統資 料之存取動作;以及 j文全應用程式界面(AP丨)係根據該媒體上之至少一識 j 6螞,藉以同意該媒體上保全資料之存取動作。 6·如申請專利範圍第165項所述之裝置,其中,該安全應 程式界面(API )係包括一第一安全應用程式界面(API 第274頁 583568 % ^------ — 六、申請專利範圍 - )及至少一額外安全應用程式界面(Αρί ),該第一安全應 =程式界面(API )係可利用該至少一額外安全應用程式 ^面(API )以進行操作,該至少一額外安全應用程式界面 AP I )係提供外加保全層,該第一安全應用程式界面 (AP I )係利用該等外加保全層以控制該内容之存取動 作。 =7·如申請專利範圍第164項所述之裝置,其中,該韌體係 j由至J/ 一應用程式界面(Ap丨)以管理内容存取動作,該 :用秋式界面(AP I )係避免一主機進行該媒體之方等 級存取。 168·如申請專利範圍第167項所述之裝置,其中,該應用程 、界面(API)係避免一主機進行該内容之方塊等級存 取。 ^ 9 ·如申请專利範圍第1 6 7項所述之裝置,其中,該應用程 二、界面(AP I )係僅能夠經由一鑑別通道進行存取動作。 1^0/如申請專利範圍第158項所述之裝置,其中,該媒體係 制可攜式媒體,包括一光學碟片,且該内容係包括原版影片 衣作内容、記錄内容、複製内容、解除鎖定内容、及解除 定内容之至少一者。 ^ :如申請專利範圍第1 6 5項所述之裝置,其中,該識別碼 係j供一金鑰盒子之一種子,該金鑰盒子係提供解除鎖定 内容及解密内容之至少一者之金鑰。 1 ^ 2 ·如申請專利範圍第1 71項所述之裝置,其中,該媒體係 、有原版影片製作内容及記錄内容之至少一者,該原版影 第275頁 583568 關連金錄盒子,係分別提 片製作内容及該記錄内容,伴隨其 供一完整存取系統。 一 173. 如申請專利範圍第171項所述之襄置,其中該 子可以與一第一媒體解除連結、並重新連結至’_;第,二餘f 以該金鑰盒子。 ^存取系統,其同時連結 174. —種原版影片製作保全預先錄製内容之方法,其包 括·· 加密該預先記錄内容;以及 連接一金鑰盒子及至少一識別碼至一媒體碟片,該金鑰盒 子係架構以使用具有該金鑰盒子之該識別碼,其中,該等^ 別碼係包括一完整識別碼及一部分識別碼之至少一者該 部分識別碼係要求,在使用該金鑰盒子前,經由一次要交^ 完成。 175·如申請專利範圍第174項所述之方法,其中,該金輪盒 子係架構以提供操作一三重資料加密標準(t r i p丨e _ )方塊之金鑰,該三重資料加密標準(triple_DES)方塊 係接收一隨機金錄產生器之一輸出,該隨機金鑰產生器係 利用該媒體碟片之該完整識別碼以進行播種,該三重資料 加密標準(triple—DES)方塊係使用具有該金鑰盒子之 該完整識別碼,藉以對該内容進行解密及加密動作。 176·如申請專利範圍第174項所述之方法,其中,該等識別 碼係包括公開及私密識別碼。 第276頁
  2. 2
    The system described in item 1 of the scope of patent application, further comprising a media, which can use the host system and the controller to operate, wherein the media holds the content in a file, which can be passed through the first At least one of a digital rights management (DRM) element, the file system element, and a second digital rights management (DRM) element for access. 2.如申請專利範圍第1項所述之系統,更包括一媒體,其可利用該主機系統及該控制器以進行操作,其中,該媒體係以檔案持有該內容,其可經由該第一數位權利管理(DRM)元件、該檔案系統元件、及一第二數位權利管理(DRM)元件之至少一者以進行存取。
  3. 3
    The system according to item 1 of the scope of patent application, wherein the content uses the first digital rights management (DRM) element and a second digital rights management (DRM) element, and uses the first digital rights management (DRM) element ( DRM) component, and one of the second digital rights management (DRM) component and the file system component for management. 3.如申請專利範圍第1項所述之系統,其中,該內容係利用該第一數位權利管理(DRM)元件及一第二數位權利管理(DRM)元件、利用該第一數位權利管理(DRM)元件、以及利用該第二數位權利管理(DRM)元件及該檔案系統元件之一者以進行管理。
  4. 4
    The system described in item 3 of the scope of patent application, wherein the first digital rights management (DRM) component manages access to pre-recorded content on a medium via a secure application programming interface (API) . 4.如申請專利範圍第3項所述之系統,其中,該第一數位權利管理(DRM)元件係經由一安全應用程式界面(API)以對一媒體上預先錄製內容之存取動作進行管理。
  5. 5
    The system according to item 3 of the scope of patent application, wherein the second digital rights management (DRM) component is via a secure application programming interface (API) associated with the first digital rights management (DRM) component, By doing so, the access to pre-recorded content on a medium is managed. 5.如申請專利範圍第3項所述之系統,其中,該第二數位權利管理(DRM)元件係經由與該第一數位權利管理(DRM)元件關連之一安全應用程式界面(API),藉以對一媒體上預先錄製內容之存取動作進行管理。
  6. 6
    The system according to item 1 of the scope of patent application, wherein the host system is operable by using a computer system, and the host system is utilizing the computer system to avoid access to the content. 6.如申請專利範圍第1項所述之系統,其中,該主機系統係可利用一電腦系統以進行操作,該主機系統係利用該電腦系統以避免該內容之存取動作。
  7. 7
    The system according to item 2 of the scope of patent application, wherein the media is operable by using the host system, and the controller is a media disc. 7.如申請專利範圍第2項所述之系統,其中,該媒體係可利用該主機系統以進行操作、且該控制器係一媒體碟片。
  8. 8
    The system according to item 1 of the scope of patent application, wherein the host system further includes an engine component, the engine component includes predetermined metadata, which cannot be accessed outside the engine, and the engine is structured to Provides an encryption security layer. 8.如申請專利範圍第1項所述之系統,其中,該主機系統更包括一引擎元件,該引擎元件係包括預定元資料,其無法在該引擎外進行存取動作,該引擎係架構以提供一加密安全層。
  9. 9
    The system according to item 1 of the scope of patent application, wherein the host system is coupled to a server which is provided to provide encrypted data to an engine element in the host system, the engine element includes a predetermined Metadata, which cannot be accessed outside the engine. 9.如申請專利範圍第1項所述之系統,其中,該主機系統係可以耦接至一伺服器,其配備以提供加密資料至該主機系統內之一引擎元件,該引擎元件係包括預定元資料,其無法在該引擎外進行存取動作。
  10. 10
    A method for preserving electronic content, the method comprising:interface a controller to provide data input and output;and coupling a host system to the controller, constructing the host system to present content under predetermined conditions, using a Navigate the agreement to operate the host system, where A host management device is operated on the host system, and the host system is operable to: construct a related component to be executed at least partially by the host system;construct a translator to provide meaning and generate commands in the host system;the architecture is at least A first digital rights management (DRM) component to provide coding and access rules for the content;and a file system component including a file system application program interface (API) to provide a logical interface between the plurality of components. 10.一種保全電子內容之方法,該方法包括:界面一控制器以提供資料之輸入及輸出;以及耦接一主機系統至該控制器,架構該主機系統以在預定條件下呈現內容,利用一導覽協定以操作該主機系統,在該 主機系統上操作一主機管理裝置,該主機系統係可操作以:架構一關連元件以由該主機系統至少部分地執行;架構一轉譯器以提供意義、並產生該主機系統內之命令;架構至少一第一數位權利管理(DRM)元件以提供該內容之編碼及存取規則;以及架構一檔案系統元件,其包括一檔案系統應用程式界面(API),藉以在複數元件間提供一邏輯界面。
  11. 11
    The method according to item 10 of the scope of patent application, further comprising:using the host system and the controller to operate a media, wherein the media holds the content in a file, which can be passed through the first digital right At least one of a management (DRM) component, the file system component, and a second digital rights management (DRM) component for accessing operations. 11.如申請專利範圍第10項所述之方法,更包括:利用該主機系統及該控制器以操作一媒體,其中,該媒體係以檔案持有該內容,其可經由該第一數位權利管理(DRM)元件、該檔案系統元件、及一第二數位權利管理(DRM)元件之至少一者以進行存取動作。
  12. 12
    The method according to item 10 of the scope of patent application, wherein the content uses the first digital rights management (DRM) element and a second digital rights management (DRM) element, and uses the first digital rights management (DRM) element ( DRM) component, and one of the second digital rights management (DRM) component and the file system component for management. 12.如申請專利範圍第10項所述之方法,其中,該內容係利用該第一數位權利管理(DRM)元件及一第二數位權利管理(DRM)元件、利用該第一數位權利管理(DRM)元件、以及利用該第二數位權利管理(DRM)元件及該檔案系統元件之一者以進行管理。
  13. 13
    The method according to item 12 of the scope of patent application, wherein the first digital rights management (DRM) component manages access to pre-recorded content on a medium via a secure application programming interface (API) . 13.如申請專利範圍第12項所述之方法,其中,該第一數位權利管理(DRM)元件係經由一安全應用程式界面(API)以對一媒體上預先錄製內容之存取動作進行管理。
  14. 14
    The method according to item 12 of the scope of patent application, wherein the second digital rights management (DRM) component is via a secure application programming interface (API) associated with the first digital rights management (DRM) component, By right Manage access to pre-recorded content on a medium. 14.如申請專利範圍第12項所述之方法,其中,該第二數位權利管理(DRM)元件係經由與該第一數位權利管理(DRM)元件關連之一安全應用程式界面(API),藉以對 一媒體上預先錄製內容之存取動作進行管理。
  15. 15
    The method according to item 10 of the scope of patent application, wherein the host system is operable by using a computer system, and the host system is utilizing the computer system to avoid access to the content. 15.如申請專利範圍第10項所述之方法,其中,該主機系統係可利用一電腦系統以進行操作,該主機系統係利用該電腦系統以避免該內容之存取動作。
  16. 18
    The method according to item 10 of the scope of patent application, wherein the host system further includes an engine element, the engine element includes predetermined metadata, which cannot be accessed outside the engine, and the engine is structured to Provides an encryption security layer. 18.如申請專利範圍第10項所述之方法,其中,該主機系統更包括一引擎元件,該引擎元件係包括預定元資料,其無法在該引擎外進行存取動作,該引擎係架構以提供一加密安全層。
  17. 20
    A method for detecting unauthorized actions on encrypted data on a media disc, the media disc comprising a first part of pre-recorded content and a second part of written content, the method comprising:reading the media An identification code on the disc, wherein the identification code includes at least one section, which is located in the first part of the pre-recorded content, the second part of the written content, and the first part of the pre-recorded content and write Into One of the second part of the content;determining whether the identification code includes a section, which is located in the second part of the written content;comparing the identification code with at least one predetermined type of identification code, wherein a section is Located in the second part of the written content;and if the identification code is one of the at least one predetermined type of identification code, detecting an unauthorized action. 20.一種偵測一媒體碟片上加密資料之未授權行動之方法,該媒體碟片係包括預先錄製內容之一第一部分及寫入內容之一第二部分,該方法包括:讀取該媒體碟片上之一識別碼,其中,該識別碼係包括至少一區段,其係位於預先錄製內容之該第一部分、寫入內容之該第二部分、以及預先錄製內容之該第一部分及寫入 內容之該第二部分之一者;決定該識別碼是否包括一區段,其位於寫入內容之該第二部分;比較該識別碼及至少一預定類型之識別碼,其中,一區段係位於寫入內容之該第二部分;以及若該識別碼係該等至少一預定類型之識別碼之一者,則偵測一未授權行動。
  18. 21
    The method according to item 20 of the scope of patent application, wherein the reading action of the identification code on the media disc is during a media disc access operation, which includes recording, playback, obtaining a playback key, At least one of copying, opening, closing, and generating actions. 21.如申請專利範圍第20項所述之方法,其中,該媒體碟片上該識別碼之讀取動作係位於一媒體碟片存取操作期間,其包括記錄、播放、取得播放金鑰、複製、開啟、關閉、以及產生動作之至少一者。
  19. 22
    The method according to item 21 of the scope of patent application, wherein the function of the media access disc operation is discontinued after the unauthorized action is detected. 22.如申請專利範圍第21項所述之方法,其中,該媒體存取碟片操作之功能係在偵測到該未授權行動後加以廢止。
  20. 23
    The method according to item 20 of the scope of patent application, wherein the identification code is one of a plurality of identification codes on the media disc, and each identification code is associated with at least one file on the media disc, and The archive includes one of pre-recorded content and written content. 23.如申請專利範圍第20項所述之方法,其中,該識別碼係該媒體碟片上複數識別碼之一者,各個識別碼係與該媒體碟片上之至少一檔案關連,該等檔案包括預先錄製內容及寫入內容之一者。
  21. 25
    The method according to item 20 of the scope of patent application, wherein the media disc is one of a media disc, an optical disc, a digital video disc, and other digital storage media. 25.如申請專利範圍第20項所述之方法,其中,該媒體碟片係一媒體碟片、一光碟、一數位影音光碟、及其他數位儲存媒體之一者。
  22. 26
    The method as described in claim 20, wherein the identification code Is pre-recorded on the media disc, and the media disc is pre-recorded. 26.如申請專利範圍第20項所述之方法,其中,該識別碼 係預先錄製在該媒體碟片上,且該媒體碟片係預先錄製的。
  23. 27
    The method according to item 20 of the scope of patent application, wherein the predetermined type indicates an identification code of the written content, and the identification code relates to a position of the written content on the media disc, It is unique to this media disc. 27.如申請專利範圍第20項所述之方法,其中,該預定類型係指示寫入內容之一識別碼,且該識別碼係有關於該寫入內容在該媒體碟片上之一位置,其係該媒體碟片所獨一無二的。
  24. 28
    The method according to item 20 of the scope of patent application, wherein the identification code is a seed of a key generator, and the key generator retrieves at least one key from a key box. The key is used for at least one of unlocking and decrypting files on a media disc. 28.如申請專利範圍第20項所述之方法,其中,該識別碼係一金鑰產生器之一種子,該金鑰產生器係由一金鑰盒子擷取至少一金鑰,該等金鑰係用於一媒體碟片上之檔案解除鎖定及解密動作之至少一者。
  25. 29
    The method according to item 20 of the scope of patent application, wherein the identification code is retrieved by a media disc and used in an engine to perform an authentication function, the authentication function executes the identification code and at least one predetermined Compare actions of type identifiers, and detect an unauthorized action. 29.如申請專利範圍第20項所述之方法,其中,該識別碼係由一媒體碟片擷取並用於一引擎中以進行一認證函數,該認證函數係執行該識別碼及至少一預定類型之識別碼之比較動作、以及偵測一未授權行動。
  26. 30
    The method according to item 20 of the scope of patent application, wherein the detection action of an unauthorized action results in the authentication function providing a failure indication. 30.如申請專利範圍第20項所述之方法,其中,一未授權行動之該偵測動作係導致提供一失敗指示之該認證函數。
  27. 31
    The method according to item 21 of the scope of patent application, wherein the detecting action of an unauthorized action causes the function of the media disc access operation to be abolished. 31.如申請專利範圍第21項所述之方法,其中,一未授權行動之該偵測動作係導致該媒體碟片存取操作之功能廢止。
  28. 32
    The method as described in item 20 of the scope of patent application, wherein the method of detecting unauthorized actions occurs when a media disc is accessed using an engine under a digital rights management agreement. 32.如申請專利範圍第20項所述之方法,其中,偵測未授權行動之該方法係發生在一媒體碟片,在一數位權利管理協定下,利用一引擎進行存取時。
  29. 33
    The method as described in claim 20, wherein the identification code is located on a media disc, which can be coupled to a host, the host being a An engine, a device embedded with an engine, a third-party digital rights management agreement, an application in an open computing environment, and one of the clearinghouse servers. 33.如申請專利範圍第20項所述之方法,其中,該識別碼係位於一媒體碟片上,其可以耦接至一主機,該主機係一 引擎、內嵌一引擎之一裝置、一第三者數位權利管理協定、一開放計算環境中之一應用程式、及一情報交換所伺服器之一者。
  30. 34
    A device for detecting unauthorized movement of encrypted data on a media disc, the media disc comprising a first part of pre-recorded content and a second part of written content, the device comprising:a device for Reading an identification code on the media disk, wherein the identification code includes at least one section, which is located in the first part of the pre-recorded content, the second part of the written content, and the first part of the pre-recorded content A part and one of the second part of the written content;a device for comparing the identification code with at least one predetermined type of identification code, wherein if the identification code includes a section, it is located in the second part of the written content Part, a section located in the second part of the written content is unauthorized;and a device for detecting an unauthorized action if the identification code is one of the at least one predetermined type of identification code. 34.一種偵測一媒體碟片上加密資料之未授權行動之裝置,該媒體碟片係包括預先錄製內容之一第一部分及寫入內容之一第二部分,該裝置包括:裝置,用以讀取該媒體磁片上之一識別碼,其中,該識別碼係包括至少一區段,其係位於預先錄製內容之該第一部分、寫入內容之該第二部分、以及預先錄製內容之該第一部分及寫入內容之該第二部分之一者;裝置,用以比較該識別碼及至少一預定類型之識別碼,其中若該識別碼包括一區段,其位於寫入內容之該第二部分,位於寫入內容之該第二部分之一區段係未授權;以及裝置,用以偵測一未授權行動,若該識別碼係該等至少一預定類型之識別碼之一者。
  31. 35
    The device according to item 34 of the scope of patent application, further comprising:a device for determining whether the identification code is a pre-recorded identification code or a copy of an identification code having a combination of pre-recorded data and written data . 35.如申請專利範圍第34項所述之裝置,更包括:裝置,用以決定該識別碼是否為一預先錄製識別碼、或具有預先錄製資料及寫入資料組合之一識別碼之一複製。
  32. 36
    The device according to item 34 of the patent application scope, wherein the device for reading the identification code comprises a media disc access element. 36.如申請專利範圍第34項所述之裝置,其中,讀取該識別碼之該裝置係包括一媒體碟片存取元件。
  33. 37
    The device described in claim 34, wherein the device that reads the identification code is operated during an access operation. 37.如申請專利範圍第34項所述之裝置,其中,讀取該識別碼之該裝置係在一存取操作期間進行操作。
  34. 38
    The device according to item 34 of the scope of patent application, wherein the identification code is one of a plurality of identification codes on a media disc, and each identification code is related to a media At least one file on the sports disc is related, and these files include one of pre-recorded content and written content. 38.如申請專利範圍第34項所述之裝置,其中,該識別碼係一媒體碟片上複數識別碼之一者,各個識別碼係與一媒 體碟片上之至少一檔案關連,該等檔案包括預先錄製內容及寫入內容之一者。
  35. 39
    The device described in claim 38, wherein at least one of the identification codes is unique to the media disc. 39.如申請專利範圍第38項所述之裝置,其中,該等識別碼之至少一者係該媒體碟片所獨一無二的。
  36. 40
    The device according to item 34 of the scope of application for a patent, wherein the identification code is a seed of an encrypted key box, and the key generator uses the identification code to retrieve at least one key, and thereby Unlock the files on the media disc. 40.如申請專利範圍第34項所述之裝置,其中,該識別碼係一加密金鑰盒子之一種子,該金鑰產生器係利用該識別碼以擷取至少一金鑰,藉以對一媒體碟片上之檔案進行解除鎖定動作。
  37. 41
    An engine structured to detect unauthorized actions on encrypted data on a media disc, the media disc comprising a first part of pre-recorded content and a second part of written content, the engine comprising:a A firmware component is disposed on a special-purpose integrated circuit (ASIC). The firmware component includes: a block structured to read an identification code on the media disc, wherein the identification code includes at least A section which is one of the first part of the pre-recorded content, the second part of the written content, and the first part of the pre-recorded content and the second part of the written content;a block, which is It is structured to compare the identification code with at least one predetermined type of identification code, wherein if the identification code includes a section, which is located in the second part of the written content, and is located in a section of the second part of the written content Unauthorized;and a block that is structured to detect an unauthorized action if the identification code is one of the at least one predetermined type of identification code. 41.一種引擎,其架構以偵測一媒體碟片上加密資料之未授權行動,該媒體碟片係包括預先錄製內容之一第一部分及寫入內容之一第二部分,該引擎包括:一韌體元件,設置於一特殊用途積體電路(ASIC)上,該韌體元件包括:一方塊,其係架構以讀取該媒體碟片上之一識別碼,其中,該識別碼係包括至少一區段,其係位於預先錄製內容之該第一部分、寫入內容之該第二部分、以及預先錄製內容之該第一部分及寫入內容之該第二部分之一者;一方塊,其係架構以比較該識別碼及至少一預定類型之識別碼,其中若該識別碼包括一區段,其位於寫入內容之該第二部分,位於寫入內容之該第二部分之一區段係未授權;以及一方塊,其係架構以偵測一未授權行動,若該識別碼係該等至少一預定類型之識別碼之一者。
  38. 42
    A computer program product, the computer program product comprising:A signal-bearing medium carrying digital information is used to include a program. The digital information includes: a block that is structured to read an identification code on the media disc, wherein the identification code includes at least one section, which Is one of the first part of the pre-recorded content, the second part of the written content, and the first part of the pre-recorded content and the second part of the written content;a box that is structured to compare the identification And at least one predetermined type of identification code, wherein if the identification code includes a section located in the second part of the written content, and a section located in the second part of the written content is unauthorized;and Block, which is structured to detect an unauthorized action if the identification code is one of the at least one predetermined type of identification code. 42.一種電腦程式產品,該電腦程式產品包括: 承載數位資訊之信號承載媒體,用以包括程式,該數位資訊包括:一方塊,其係架構以讀取該媒體碟片上之一識別碼,其中,該識別碼係包括至少一區段,其係位於預先錄製內容之該第一部分、寫入內容之該第二部分、以及預先錄製內容之該第一部分及寫入內容之該第二部分之一者;一方塊,其係架構以比較該識別碼及至少一預定類型之識別碼,其中若該識別碼包括一區段,其位於寫入內容之該第二部分,位於寫入內容之該第二部分之一區段係未授權;以及一方塊,其係架構以偵測一未授權行動,若該識別碼係該等至少一預定類型之識別碼之一者。
  39. 43
    A method of identifying a location associated with a manufacturer of a media disc, the media disc holding content, the method comprising:providing instructions for the media disc;During the installation of these instructions to a host, an identification code is installed on the media disc, the identification code includes a code associated with the manufacturer;and the information is read after the data is transmitted to a server Code to find a location associated with the manufacturer, the location is associated with the manufacturer of the media disc and is independent of any manufacturer not associated with the media disc. 43.一種識別一位置之方法,該位置於與一媒體碟片之一製造商關連,該媒體碟片係持有內容,該方法包括:提供該媒體碟片之指令;在該媒體碟片根據該等指令以安裝至一主機期間,安裝一識別碼於該媒體碟片上,該識別碼係包括與該製造商關連之一程式碼;以及待傳輸資料至一伺服器後,讀取該識別碼以找到與該製造商關連之一位置,該位置係關連於該媒體碟片之該製造商且獨立於與該媒體碟片沒有關連之任何製造商。
  40. 44
    The method as described in item 43 of the scope of patent application, wherein the instructions of the media disc include:identifying a manufacturer who purchased the media disc. 44.如申請專利範圍第43項所述之方法,其中,該媒體碟片之該等指令係包括:識別購買該媒體碟片之一製造商。
  41. 45
    The method according to item 43 of the scope of patent application, wherein the media is purchased The identification action of the manufacturer of the physical disc includes providing a code, a global resource locator (URL), an encryption key associated with the manufacturer in the instructions, and an association with the manufacturer. One of a part of an encryption key. 45.如申請專利範圍第43項所述之方法,其中,購買該媒 體碟片之該製造商之該識別動作係包括:在該等指令中提供一程式碼、一全球資源定位器(URL)、與該製造商關連之一加密金鑰、及與該製造商關連之一加密金鑰之一部分之一者。
  42. 46
    A system for identifying a location associated with a manufacturer of a media disc, the media disc holding content, the system including:instructions for the media disc;and a software installation component, which Related to the media disc, the software installation element can be exemplified during the installation of the media disc to a host according to the instructions. The software installation element is operable to install an identification code on the media disc, the The identification code includes a code associated with the manufacturer, and the identification code relates to a location of the manufacturer, so that a connection between the host and a server is operable to open the location. 46.一種識別一位置之系統,該位置於與一媒體碟片之一製造商關連,該媒體碟片係持有內容,該系統包括:該媒體碟片之指令;以及一軟體安裝元件,其關連於該媒體碟片,該軟體安裝元件係可在該媒體碟片根據該等指令安裝至一主機期間舉例說明,該軟體安裝元件係可操作以安裝該媒體碟片上之一識別碼,該識別碼係包括與該製造商關連之一程式碼,該識別碼關連該製造商之一位置,藉以使該主機及一伺服器間之一連接可操作以開啟該位置。
  43. 47
    The system according to item 46 of the scope of patent application, wherein the instructions of the media disc include:identifying a manufacturer who purchases the media disc. 47.如申請專利範圍第46項所述之系統,其中,該媒體碟片之該等指令係包括:識別購買該媒體碟片之一製造商。
  44. 48
    The system according to item 46 of the scope of patent application, wherein the identification action of the manufacturer who purchased the media disc includes:providing a code, a global resource locator (URL) in the instructions , One of the cryptographic keys associated with the manufacturer and one of the cryptographic keys associated with the manufacturer. 48.如申請專利範圍第46項所述之系統,其中,購買該媒體碟片之該製造商之該識別動作係包括:在該等指令中提供一程式碼、一全球資源定位器(URL)、與該製造商關連之一加密金鑰、及與該製造商關連之一加密金鑰之一部分之一者。
  45. 49
    The system according to item 46 of the scope of patent application, wherein the location is an Internet location that includes a web page to unlock the stored content on the media disc, and the Internet location provides Selective supply to enable the manufacturer to buy on the Internet. 49.如申請專利範圍第46項所述之系統,其中,該位置係一網際網路位置,其包括網頁以對該媒體碟片上的儲存內容進行解除鎖定動作,該網際網路位置更提供選擇性供應,藉以讓該製造商能夠在網際網路上購買。
  46. 50
    The system according to item 46 of the scope of patent application, wherein the host is an engine, a device embedded with an engine, a third-party digital rights management agreement, and an application program running in an open computing environment. One of them. 50.如申請專利範圍第46項所述之系統,其中,該主機係一引擎、內嵌一引擎之一裝置、一第三者數位權利管理協定、以及一開放計算環境中執行之一應用程式之一者。
  47. 51
    A method of identifying a location via a media disc, the media disc including at least a writable portion and a non-rewritable portion, the method comprising:writing the location to the writable portion;distributing at least A media disc is given to at least one entity, the location is related to the media discs to the entities;and if one of the media discs returns, the position is changed according to predetermined conditions. 51.一種經由一媒體碟片識別一位置之方法,該媒體碟片係包括至少一可寫入部分及一不可重寫部分,該方法包括:將該位置寫入該可寫入部分;散佈至少一媒體碟片給至少一實體,該位置係關連該等媒體碟片至該等實體;以及若發生該等媒體碟片之一返回,則根據預定條件以改變該位置。
  48. 53
    The method according to item 51 of the scope of patent application, wherein the change of position is performed by a content provider, and the content provider receives the media discs, including at least one media disc, and After the change, the returned media discs are distributed to the same or different entities of the entities. 53.如申請專利範圍第51項所述之方法,其中,該位置之改變動作係由一內容提供者執行,該內容提供者係接收該等媒體碟片,包括至少一媒體碟片、以及在該改變動作後,將該等返回媒體碟片散佈至該等實體之相同或不同實體。
  49. 54
    The method as described in item 53 of the scope of patent application, wherein the dissemination action is based on a lease contract for one of the media discs, and the lease contract is for the return of unsold media discs. 54.如申請專利範圍第53項所述之方法,其中,該散佈動作係根據該等媒體碟片之一租賃合約,該租賃合約係同意未售出媒體碟片之返回。
  50. 55
    A system for identifying a position, the system comprising:a media disc having at least a writable portion and a non-rewritable portion, the media disc writing the position into the writable portion;Distribute at least one media disc to at least one entity, the location is related to the media Body discs to those entities;and if one of the media discs returns occurs, the location is changed according to predetermined conditions. 55.一種識別一位置之系統,該系統係包括:一媒體碟片,其具有至少一可寫入部分及一不可重寫部分,該媒體碟片係將該位置寫入該可寫入部分;散佈至少一媒體碟片給至少一實體,該位置係關連該等媒 體碟片至該等實體;以及若該等媒體碟片之一返回發生時,則根據預定條件以改變該位置。
  51. 56
    The system as described in claim 55, wherein the media disc is one of a media disc, an optical disc, a digital video disc, and other digital storage media. 56.如申請專利範圍第55項所述之系統,其中,該媒體碟片係一媒體碟片、一光碟、一數位影音光碟、及其他數位儲存媒體之一者。
  52. 58
    A computer program product, the computer program product comprising:a signal bearing medium having a program for: as an example during installation of the signal bearing medium to a host according to instructions;and installing an identification code to the signal bearing In the media, the identification code includes a code associated with a manufacturer of hidden content on the signal bearing medium, and the identification code is associated with a location of the manufacturer, so that one of the host and a server The connection is operable to open the position. 58.一種電腦程式產品,該電腦程式產品係包括:信號承載媒體,其具有程式,用以:在該信號承載媒體根據指令安裝至一主機期間做為範例;以及安裝一識別碼至該信號承載媒體上,該識別碼係包括與該信號承載媒體上隱藏內容之一製造商關連之一程式碼,該識別碼係關連於該製造商之一位置,藉以使該主機及一伺服器間之一連接可操作以開啟該位置。
  53. 59
    A method for changing security data on a storage medium, the method comprising:establishing a secure conversation with a host;receiving and receiving a command to unlock the security data via a communication channel, which is based on at least one content storage model Management;and unlocking the security data, wherein the command is in response to a command on the media disc, the identification code is structured to manage the access action of the security data, and at least one content storage model is A secure content management device. 59.一種改變一儲存媒體上保全資料之方法,該方法包括:與一主機建立一安全對話;接收,經由通信通道,對該保全資料進行解除鎖定之一命令,其係由至少一內容儲存模型進行管理;以及對該保全資料進行解除鎖定,其中,該命令係回應於該媒體碟片上之一命令,該識別碼係架構以管理該保全資料之存取動作,且至少一內容儲存模型係一安全內容管理裝置。
  54. 62
    The method according to item 59 of the scope of patent application, further comprising:receiving, by the host, an instruction to indicate the content to be unlocked. 62.如申請專利範圍第59項所述之方法,更包括:由該主機接收一指示,藉以表示欲解除鎖定之內容。
  55. 63
    The method as described in item 59 of the scope of patent application, further comprising:determining that the content to be unlocked is achieved by scanning a directory structure and paying attention to security information. 63.如申請專利範圍第59項所述之方法,更包括:決定欲解除鎖定之內容係透過掃描一目錄結構及注意安全資料以達到。
  56. 67
    The method according to item 59 of the scope of patent application, wherein the data access operation is managed by a file system. 67.如申請專利範圍第59項所述之方法,其中,該資料之存取動作係由一檔案系統進行管理。
  57. 68
    A system structured to perform an unlocking action on security data on a storage medium, the system comprising:a multiple content storage model for security data stored on the storage medium;and an engine capable of performing security data Perform an unlock operation, wherein the engine adjusts the attributes of the data on the storage medium, so as to perform an unlock operation on the data according to a command, and a content storage model The security data is unlocked. 68.一種架構以對一儲存媒體上安全資料進行解除鎖定動作之系統,該系統係包括:複數內容儲存模型,用於該儲存媒體上儲存之保全資料;以及一引擎,其係能夠對保全資料進行解除鎖定動作,其中,該引擎係調整該儲存媒體上該資料之屬性,藉以依據對該資料進行解除鎖定動作之一命令,根據一內容儲存模型以對 該保全資料進行解除鎖定動作。
  58. 70
    The system described in claim 69, wherein the communication channel is one of an Internet channel, a satellite communication channel, a wireless channel, and a wired channel. 70.如申請專利範圍第69項所述之系統,其中,該通信通道係一網際網路通道、一衛星通信通道、一無線通道、及一有線通道之一者。
  59. 73
    The system as described in claim 68, wherein the content storage model is one of a proprietary and a third party digital rights management agreement. 73.如申請專利範圍第68項所述之系統,其中,該內容儲存模型係一專有及一第三者數位權利管理協定之一者。
  60. 74
    The system according to item 68 of the scope of patent application, wherein access to the data is managed by a file system. 74.如申請專利範圍第68項所述之系統,其中,該資料之存取動作係由一檔案系統進行管理。
  61. 75
    A computer program product comprising:a storage medium;a plurality of content storage models for data stored on the storage medium;a computer program comprising: instructions for adjusting the data on the storage medium Attributes to unlock the security data based on at least one content storage model;instructions that communicate with a host via a communication channel;and instructions that the host receives a command to secure the data Unlock operation is performed. 75.一種電腦程式產品,其包括:一儲存媒體;複數內容儲存模型,用於該儲存媒體上儲存之資料;一電腦程式,該電腦程式係包括:指令,其係調整該儲存媒體上該資料之屬性,藉以對根據至少一內容儲存模型之保全資料進行解除鎖定動作;指令,其係經由一通信通道與一主機進行通信;以及指令,其係由該主機接收一命令,藉以對該保全資料進行解除鎖定動作。
  62. 76
    The computer program product according to item 75 of the scope of patent application, wherein the communication channel is one of an Internet channel, a satellite communication channel, a wireless channel, and a wired channel. 76.如申請專利範圍第75項所述之電腦程式產品,其中,該通信通道係一網際網路通道、一衛星通信通道、一無線通道、及一有線通道之一者。
  63. 77
    The computer program product described in item 75 of the scope of patent application, wherein the computer program further includes:instructions that determine the information to be unlocked by tracking a directory structure and identifying security data. 77.如申請專利範圍第75項所述之電腦程式產品,其中,該電腦程式更包括:指令,其係藉著追蹤一目錄結構及識別保全資料,藉以決定欲解除鎖定之資料。
  64. 78
    The computer program product described in item 75 of the scope of patent application, wherein the computer program further comprises:instructions for establishing a secure dialogue with the host. 78.如申請專利範圍第75項所述之電腦程式產品,其中,該電腦程式更包括:指令,用以與該主機建立一安全對話。
  65. 79
    The computer program product described in item 75 of the scope of patent application, wherein the computer program further includes:an instruction for decrypting the order for unlocking the secure data. 79.如申請專利範圍第75項所述之電腦程式產品,其中,該電腦程式更包括:指令,用以解密對該安全資料進行解除鎖定動作之該命令。
  66. 80
    The computer program product described in claim 75, wherein the content storage model includes at least two digital rights management agreements. 80.如申請專利範圍第75項所述之電腦程式產品,其中,該等內容儲存模型係包括至少二數位權利管理協定。
  67. 81
    The computer program product described in claim 75, wherein at least one content storage model is one of a proprietary and a third-party digital rights management agreement. 81.如申請專利範圍第75項所述之電腦程式產品,其中,至少一內容儲存模型係一專有及一第三者數位權利管理協定之一者。
  68. 82
    A device for unlocking security data on a storage medium, the device comprising:a device for establishing a secure conversation with a host;a device for receiving and unlocking the security data through a communication channel A command of a lock action, wherein the security data is managed by at least one content storage model;and a device for unlocking the security data on the storage medium, wherein the command is in response to the security data on the media An identification code It is configured to manage the access action of the security data, and at least one content storage model is a secure content management device. 82.一種對一儲存媒體上安全資料進行解除鎖定之裝置,該裝置係包括:裝置,用以與一主機建立一安全對話;裝置,用以接收,經由一通信通道,對該保全資料進行解除鎖定動作之一命令,其中,該保全資料係由至少一內容儲存模型進行管理;以及裝置,用以對該儲存媒體上該保全資料進行解除鎖定動作,其中,該命令係回應於該媒體上之一識別碼,該識別碼係架 構以管理該保全資料之存取動作,且至少一內容儲存模型係一安全內容管理裝置。
  69. 83
    A method of identifying a device, the method comprising:receiving a voucher by the device, the voucher including a plurality of fields including a field to hold a digital signature of a voucher management center;confirming the voucher Among the digital signatures, the confirmation action includes at least: using the public key of the certificate management center to confirm the digital signature of the certificate management center;and using the public key of a device to confirm the digital signature of a device Receiving authentication information from a source that identifies at least one piece of information in the certificate as valid or invalid according to predetermined conditions;and if the digital signatures are confirmed to be valid, transmitting a conversation key to The device is used to establish a secure communication channel. 83.一種鑑別一裝置之方法,該方法係包括:由該裝置接收一憑證,該憑證係包括複數欄位,其包括一欄位以持有一憑證管理中心之一數位簽章;確認該憑證中之該等數位簽章,該確認動作係至少包括:利用該憑證管理中心之公開金鑰以確認該憑證管理中心之數位簽章;以及利用一裝置之公開金鑰以確認一裝置之數位簽章;由一來源接收認證資料,該認證資料係根據預定條件以識別該憑證中之至少一資料為有效或無效的;以及若該等數位簽章確認為有效的,則傳輸一對話金鑰至該裝置,藉以建立一安全通信通道。
  70. 85
    The method according to item 83 of the scope of patent application, wherein the device is an engine, a device embedded with an engine, a third-party digital rights management agreement, an application program executed in an open computing environment, And one of the clearinghouse servers, the certificate is used to identify at least one secure application programming interface (API), whereby an application that can utilize the device for operation can perform an access operation. 85.如申請專利範圍第83項所述之方法,其中,該裝置係一引擎、內嵌一引擎之一裝置、一第三者數位權利管理協定、一開放計算環境中執行之一應用程式、及一情報交換所伺服器之一者,該憑證係用以識別至少一安全應用程式界面(API),藉此,可利用該裝置以進行操作之一應用程式係可以進行存取動作。
  71. 86
    The method according to item 83 of the scope of patent application, wherein the certificate is digitally signed by a private key assigned according to a device category, the device category includes:an engine, an engine embedded, and no external Digital I / O Port Device, a built-in engine, a device with an I / O port, a device application without a built-in engine, a third-party digital rights management agreement, and a clearinghouse server. 86.如申請專利範圍第83項所述之方法,其中,該憑證係由根據一裝置類別指派之一私密金鑰進行數位簽章,該裝置類別係包括:引擎、內嵌一引擎,不具外部數位I/O埠之 裝置、內嵌一引擎、具有I/O埠之裝置、未內嵌一引擎之裝置應用程式、第三者數位權利管理協定、及情報交換所伺服器。
  72. 87
    The method according to item 83 of the scope of patent application, wherein the certificate action of the device includes:a certificate connects a host to a second host in a second host secure communication channel, and the certificate action is to agree with the host and the Copy function between one of the second hosts. 87.如申請專利範圍第83項所述之方法,其中,該裝置之憑證動作係包括:憑證連接一主機於第二主機安全通信通道之一第二主機,該憑證動作係同意該主機及該第二主機間之一複製函數。
  73. 88
    The method according to item 83 of the scope of patent application, wherein the information in the voucher is used to specify at least one of a product category, a product line, a model, a revision, and a serial number of the device. 88.如申請專利範圍第83項所述之方法,其中,該憑證中之該資料係用來指定該裝置之一產品類別、一產品線、一模型、一修訂、一序號之至少一者。
  74. 89
    The method according to item 88 of the scope of application for a patent, wherein the source certification data is compared with the data in the certificate, whereby the product category, the product line, the model, the amendment, and the device of the device are compared, and At least one of the serial numbers is identified as invalid. 89.如申請專利範圍第88項所述之方法,其中,該來源認證資料係與該憑證中之該資料比較,藉以將該裝置之該產品類別、該產品線、該模型、該修訂、及該序號之至少一者識別為無效的。
  75. 90
    The method according to item 83 of the scope of patent application, wherein the certificate includes a certificate management center identifier field, a version field, a signature key identifier field, an exposure method field, A company field, a model identification field, a revision field, a metadata identification field, a device digital signature key field, a certificate management center digital signature field, a serial number field, a At least one of an agreement public key field and a device digital signature field, wherein the digital signature of the certificate management center confirms at least one field in the certificate, and the device digital signature confirms the certificate At least one of the fields. 90.如申請專利範圍第83項所述之方法,其中,該憑證係包括一憑證管理中心識別碼欄位、一版本欄位、一簽章金鑰識別碼欄位、一曝露方法欄位、一公司欄位、一模型識別碼欄位、一修訂欄位、一元資料識別碼欄位、一裝置數位簽章金鑰欄位、一憑證管理中心數位簽章欄位、一序號欄位、一協定公開金鑰欄位、及一裝置數位簽章欄位之至少一者,其中,該憑證管理中心數位簽章係確認該憑證中之至少一欄位,且該裝置數位簽章係確認該憑證中之至少一欄位。
  76. 91
    The method according to item 83 of the scope of patent application, wherein the certificate management The center allows an entity to receive the certificate and control the quality of the device through an invalid error or potentially defective device. 91.如申請專利範圍第83項所述之方法,其中,該憑證管理 中心係讓一實體接收該憑證,並透過無效錯誤或具有潛在缺陷的裝置,藉以控制該裝置之品質。
  77. 92
    The method according to item 88 of the scope of patent application, wherein the certificate further includes a field provided by a device manufacturer, including a public key of the company, wherein the public key of the company is digitally provided by the certificate management center. signature. 92.如申請專利範圍第88項所述之方法,其中,該憑證更包括一裝置製造商提供之欄位,包括該公司公開金鑰,其中,該公司公開金鑰係由該憑證管理中心數位簽章。
  78. 93
    The method according to item 88 of the scope of patent application, wherein the certificate further includes fields provided by the device manufacturer, and the fields include the device public key, wherein the device public key is provided by the device Digitally signed company seal. 93.如申請專利範圍第88項所述之方法,其中,該憑證更包括一裝置製造商提供之欄位,該等欄位包括該裝置公開金鑰,其中,該裝置公開金鑰係由該公司數位簽章。
  79. 96
    The method according to item 95 of the patent application scope, wherein the set of methods includes a digital rights management (DRM) method, which includes a copy method, a recording method, a playback method, and a method for reading secure metadata , At least one of a method of writing secure metadata, and a method of unlocking, the digital rights management (DRM) methods are operable according to one type of the device. 96.如申請專利範圍第95項所述之方法,其中,該組方法係包括數位權利管理(DRM)方法,其包括一複製方法、一記錄方法、一播放方法、一讀取安全元資料方法、一寫入安全元資料方法、及一解除鎖定方法之至少一者,該等數位權利管理(DRM)方法係可根據該裝置之一類型以進行操作。
  80. 97
    The method according to item 96 of the patent application scope, wherein:the unlocking method is related to a clearing house server;the copying method is related to an engine, and a second digital rights management can be used One of the first digital rights management (DRM) applications;and the recording method is related to a player, an original video production tool, an information station, and an information exchange At least one of the servers. 97.如申請專利範圍第96項所述之方法,其中:該解除鎖定方法係關連於一情報交換所伺服器;該複製方法係關連於一引擎、及可利用一第二數位權利管 理(DRM)應用程式以進行操作之一第一數位權利管理(DRM)應用程式之一者;以及該記錄方法係關連於一播放器、一原版影片製作工具、一資訊站、及一情報交換所伺服器之至少一者。
  81. 98
    The method according to item 83 of the scope of patent application, wherein each column holds 326 bits of 163-bit elliptic curve encryption. 98.如申請專利範圍第83項所述之方法,其中,各個欄位係持有163位元橢圓曲線加密之326位元數位。
  82. 99
    The method as described in claim 83, wherein the certificate management center public key refers to a field of the certificate. 99.如申請專利範圍第83項所述之方法,其中,該憑證管理中心公開金鑰係參照該憑證之一欄位。
  83. 101
    A device for a certificate-device, the device comprising:a device that receives a certificate request from the device, the certificate request includes a plurality of fields, including a field holding an agreement public key;the device, uses To confirm the digital signature in the certificate, the confirmation action includes at least: using the certificate management center public key to confirm the certificate management center digital signature;and using a device public key in the certificate to confirm a device A digital signature;a device that receives authentication data from a source that identifies at least one piece of data in the certificate as valid or invalid according to a predetermined condition;and a device that transmits a session key to the device To establish a secure communication channel when the digital signatures are confirmed to be valid. 101.一種憑證一裝置之裝置,該裝置包括:裝置,其係由該裝置接收一憑證要求,該憑證要求係包括複數欄位,包括持有一協定公開金鑰之一欄位;裝置,用以確認該憑證中之數位簽章,該確認動作係至少包括:利用該憑證管理中心公開金鑰以確認該憑證管理中心數位簽章;以及利用該憑證中之一裝置公開金鑰以確認一裝置數位簽章;裝置,其係由一來源接收認證資料,該認證資料係根據預定條件以識別該憑證中之至少一資料為有效或無效的;以及裝置,其係傳輸一對話金鑰至該裝置,藉以建立一安全通信通道,當該等數位簽章係確認為有效的。
  84. 102
    An engine with a certificate-host architecture, the engine comprising:a firmware component, comprising: A block structured to receive a certificate by the host, the certificate includes a plurality of fields, including a field holding an agreement public key;a block, structured to confirm at least one digital signature in the certificate At least: a certificate management center digital signature using a certificate management center public key;and a device digital signature using a device public key in the certificate;and a block that is structured by a A source receives authentication data that identifies at least one piece of data in the certificate as valid or invalid according to predetermined conditions;and a block that is structured to transmit a session key to the device to establish a secure communication channel , When such digital signatures are confirmed to be valid. 102.一種引擎,其架構以憑證一主機,該引擎係包括:一韌體元件,包括: 一方塊,其架構以由該主機接收一憑證,該憑證係包括複數欄位,包括持有一協定公開金鑰之一欄位;一方塊,其係架構以確認該憑證中之至少一數位簽章,其至少包括:利用一憑證管理中心公開金鑰之一憑證管理中心數位簽章;以及利用該憑證中一裝置公開金鑰之一裝置數位簽章;以及一方塊,其係架構以由一來源接收認證資料,該認證資料係根據預定條件以識別該憑證中之至少一資料為有效或無效的;以及一方塊,其係架構以傳輸一對話金鑰至該裝置,藉以建立一安全通信通道,當該等數位簽章係確認為有效的。
  85. 103
    A computer program product, the computer program product comprising:a signal bearing medium carrying digital information, which holds a firmware component, the firmware component includes: a block, which is structured to receive a certificate by the device , The certificate includes a plurality of fields, including a field holding an agreement public key;a box, which is structured to confirm the digital signature in the certificate, which includes at least: using the certificate management center public key A certificate management center digital signature;and a device digital signature using a device public key in the certificate;and a block that is structured to receive authentication data from a source that is identified based on predetermined conditions At least one of the information in the voucher is valid or invalid And a block, which is structured to transmit a conversation key to the device, thereby establishing a secure communication channel when the digital signatures are confirmed to be valid. 103.一種電腦程式產品,該電腦程式產品係包括:承載數位資訊之信號承載媒體,其持有一韌體元件,該韌體元件係包括:一方塊,其係架構以由該裝置接收一憑證,該憑證係包括複數欄位,包括持有一協定公開金鑰之一欄位;一方塊,其係架構以確認該憑證中之數位簽章,其至少包括:利用該憑證管理中心公開金鑰之一憑證管理中心數位簽章;以及利用該憑證中一裝置公開金鑰之一裝置數位簽章;以及一方塊,其係架構以由一來源接收認證資料,該認證資料係根據預定條件以識別該憑證中之至少一資料為有效或無效 的;以及一方塊,其係架構以傳輸一對話金鑰至該裝置,藉以建立一安全通信通道,當該等數位簽章係確認為有效的。
  86. 104
    The computer program product described in item 103 of the scope of patent application, wherein the certificate management center public key refers to a field of the certificate. 104.如申請專利範圍第103項所述之電腦程式產品,其中,該憑證管理中心公開金鑰係參照該憑證之一欄位。
  87. 105
    The computer program product according to item 103 of the scope of patent application, wherein the public key of the certificate management center is located in the firmware component. 105.如申請專利範圍第103項所述之電腦程式產品,其中,該憑證管理中心公開金鑰係位於該韌體元件。
  88. 106
    A method for abolishing a device, the method comprising:receiving a voucher by the device, the voucher including at least one field;at least one field holding a signature;attempting to confirm the signature;receiving by a source A revocation list that identifies at least one piece of information on the voucher as valid or invalid, the data includes at least one field of the voucher;and if at least one of the seals fails to identify a seal and If at least one piece of data is confirmed to be invalid, avoid transmitting a conversation key to the device, which is necessary for establishing a secure communication channel. 106.一種廢止一裝置之方法,該方法係包括:由該裝置接收一憑證,該憑證係包括至少一欄位;至少一欄位持有一簽章;嘗試確認該簽章;由一來源接收一廢止表列,該廢止表列係識別該憑證上之至少一資料為有效或無效的,該資料係包括該憑證之至少一欄位;以及若至少一簽章中有一簽章無法成功識別且至少一資料係確認為無效的,則避免傳輸一對話金鑰至該裝置,該對話金鑰係建立一安全通信通道所必須。
  89. 107
    The method according to item 106 of the scope of patent application, wherein the revocation list is evaluated when the file is accessed. 107.如申請專利範圍第106項所述之方法,其中,該廢止表列係在檔案存取時加以評量。
  90. 108
    The method according to item 107 of the scope of patent application, wherein the revocation list is stored when the file is generated. 108.如申請專利範圍第107項所述之方法,其中,該廢止表列係在檔案產生時加以儲存。
  91. 109
    The method according to item 106 of the scope of patent application, wherein each file has a revocation list, and a plurality of files with multiple revocation lists have duplicate items. 109.如申請專利範圍第106項所述之方法,其中,各個檔案係具有一廢止表列,並且,具有複數廢止表列之複數檔案係具有重覆項目。
  92. 110
    The method as described in item 109 of the scope of patent application, wherein the repetitive items in the multiple abolition list are stored by collectively storing the details and providing each file with a listed identification code or index to Restrictions are made, where the list's identification code or index refers to a location related to the complete details of the revocation information. 110.如申請專利範圍第109項所述之方法,其中,複數廢止表列中之該等重覆項目係藉著集中儲存該等細節、並提供各個檔案以一表列之識別碼或指標以進行限制,其中,該表列之識別碼或指標係參照與廢止資訊之完整細節有關之一位置。
  93. 111
    The method according to item 110 of the scope of patent application, wherein the revocation information can be stored by the revocation node, and the revocation list associated with a file can be stored as a list of revocation node identification codes. 111.如申請專利範圍第110項所述之方法,其中,該廢止資訊係可以由廢止節點儲存,並且,與一檔案關連之該廢止表列係可以儲存為一表列之廢止節點識別碼。
  94. 112
    The method as described in item 111 of the scope of patent application, wherein each abolition node includes a listed clause and a rule combining these clauses to determine the evaluation of the node. 112.如申請專利範圍第111項所述之方法,其中,各個廢止節點係包括一表列之子句及組合該等子句之一規則,藉以決定該節點之評量。
  95. 113
    The method according to item 112 of the scope of patent application, wherein the revocation results are one of obtaining a playback key, playing, recording, copying, opening, closing, generating, obtaining metadata, and setting metadata Make the final decision. 113.如申請專利範圍第112項所述之方法,其中,該等廢止結果係由取得播放金鑰、播放、記錄、複製數、開啟、關閉、產生、取得元資料、及設定元資料之一者進行最終決定。
  96. 116
    The method according to item 106 of the scope of patent application, wherein the revocation list is maintained by a server so that a content presentation device that communicates with a server can receive an update revocation list that is directly transmitted to the device. Column. 116.如申請專利範圍第106項所述之方法,其中,該廢止表列係由一伺服器維護,藉以使與一伺服器進行通信之內容表現裝置能夠接收直接傳送至該裝置之更新廢止表列。
  97. 117
    The method according to item 106 of the scope of patent application, wherein the plurality of revocation lists are based on one-by-one files to be stored on the medium, so that the At least one file can have a revocation list associated with the file. 117.如申請專利範圍第106項所述之方法,其中,複數廢止表列係基於逐一檔案以儲存於媒體上,藉以使該媒體上之 至少一檔案能夠具有與該檔案關連之一廢止表列。
  98. 118
    The method according to item 117 of the scope of patent application, wherein the revocation list is to perform an access operation during a combination of a file access procedure and an authentication and a file access procedure. 118.如申請專利範圍第117項所述之方法,其中,該廢止表列係在一檔案存取程序、以及一鑑別及一檔案存取程序之一組合期間進行存取動作。
  99. 121
    The method according to item 106 of the scope of patent application, wherein the revocation action of a content presentation device includes at least:the revocation action of at least one public key, wherein the revocation action of a public key is the revocation of any corresponding action. signature. 121.如申請專利範圍第106項所述之方法,其中,一內容表現裝置之廢止動作係至少包括:至少一公開金鑰之廢止動作,其中,一公開金鑰之廢止動作係廢止任何對應之簽章。
  100. 123
    The method according to item 106 of the scope of patent application, wherein the revocation information is centralized. 123.如申請專利範圍第106項所述之方法,其中,該廢止資訊係集中放置。
  101. 127
    The method according to item 106 of the scope of patent application, wherein the certificate is assigned a private key for signature according to a device category, and the device category includes:an engine, an engine embedded and no external digital I / O port components, a built-in engine with digital I / O ports, and host applications without an engine. 127.如申請專利範圍第106項所述之方法,其中,該憑證係根據一裝置類別指派之一私密金鑰以簽章,該裝置類別係包括:引擎、內嵌一引擎且沒有外部數位I/O埠之元件、內嵌一擎且具有數位I/O埠之元件、及未內嵌一引擎之主機應用程式。
  102. 128
    The method according to item 106 of the scope of patent application, wherein the information in the voucher specifies at least one of a product category, a product line, a model, a revision, and a serial number of the device. 128.如申請專利範圍第106項所述之方法,其中,該憑證中之該資料係指定該裝置之一產品類別、一產品線、一模型、一修訂、及一序號之至少一者。
  103. 129
    The method as described in item 128 of the scope of patent application, wherein the source certification data is compared with the data in the certificate to thereby the product category, the product line, the model, the amendment, and the device of the device At least one of the serial numbers is identified as invalid. 129.如申請專利範圍第128項所述之方法,其中,來源認證資料係與該憑證中之該資料比較,藉以將該裝置之該產品類別、該產品線、該模型、該修訂、及該序號之至少一者識別為無效的。
  104. 130
    The method according to item 129 of the scope of patent application, wherein the voucher includes at least one of the following fields, which includes:certificate management center identification code, version, certificate management center public key, and certificate management center disclosure Key ID, exposure method, company, model ID, revision, metadata ID, host signature public key, certificate management center signature, serial number, agreement key, and host signature, of which the certificate management The central signature confirms at least one field in the certificate, and the host signature confirms at least one field in the certificate. 130.如申請專利範圍第129項所述之方法,其中,該憑證係包括下列欄位之至少一者,其包括:憑證管理中心識別碼、版本、憑證管理中心公開金鑰、憑證管理中心公開金鑰識別碼、曝露方法、公司、模型識別碼、修訂、元資料識別碼、主機簽章公開金鑰、憑證管理中心簽章、序號、協定金鑰、及主機簽章,其中,該憑證管理中心簽章係確認該憑證中之至少一欄位,且該主機簽章係確認該憑證中之至少一欄位。
  105. 135
    The method according to item 134 of the scope of patent application, wherein the set of methods includes digital rights management (DRM) methods, copying, recording, playing, reading security metadata, writing security metadata, and unlocking , And these methods can be operated according to one type of the device. 135.如申請專利範圍第134項所述之方法,其中,該組方法係包括數位權利管理(DRM)方法、複製、記錄、播放、讀取安全元資料、寫入安全元資料、及解除鎖定,且該等方法係可根據該裝置之一類型以進行操作。
  106. 137
    The method according to item 106 of the scope of patent application, wherein each field It is a 326-bit value that holds a 163-bit elliptic curve encryption. 137.如申請專利範圍第106項所述之方法,其中,各個欄位 係持有163位元橢圓曲線加密之326位元數值。
  107. 138
    A device for abolishing a host, the device comprising:a device that receives a certificate by a host, the certificate includes a plurality of fields, including one of the agreement public keys held by a certificate management center signature Field;device for confirming the signature on the certificate, the confirmation action includes: using the agreement public key to confirm the certificate management center signature;and using a host public key on the certificate to confirm a Host signature;device that receives authentication data from a source that identifies at least one piece of data on the certificate as valid or invalid according to a revocation list;and device that avoids transmitting a session key Go to the host to establish a secure communication channel if the signatures are invalid. 138.一種廢止一主機之裝置,該裝置係包括:裝置,其係由一主機接收一憑證,該憑證係包括複數欄位,包括持有一憑證管理中心簽章之一協定公開金鑰之一欄位;裝置,用以確認該憑證上之簽章,該確認動作係包括:利用該協定公開金鑰以確認該憑證管理中心簽章;以及利用該憑證上之一主機公開金鑰以確認一主機簽章;裝置,其係由一來源接收認證資料,該認證資料係根據一廢止表列以識別該憑證上之至少一資料為有效或無效的;以及裝置,其係避免傳輸一對話金鑰至該主機以建立一安全通信通道,若該等簽章係無效的。
  108. 139
    An engine structured to abolish a host, the engine comprising:a block, which is structured to receive a certificate from a host, the certificate includes a plurality of fields, including a certificate signed by a certificate management center A field of an agreement public key;a block that is structured to confirm the signature on the certificate, the confirmation action includes: using the agreement public key to confirm the certificate management center signature;and using the certificate A previous host public key confirms a host signature;a box that is structured to receive authentication data from a source, the authentication data is based on a revocation list to identify at least one piece of data on the certificate as valid or invalid ;And A block that is structured to avoid transmitting a session key to the host to establish a secure communication channel if the signatures are invalid. 139.一種引擎,其係架構以廢止一主機,該引擎係包括:一方塊,其係架構以由一主機接收一憑證,該憑證係包括複數欄位,包括持有一憑證管理中心簽章之一協定公開金鑰之一欄位;一方塊,其係架構以確認該憑證上之簽章,該確認動作係包括:利用該協定公開金鑰以確認該憑證管理中心簽章;以及利用該憑證上之一主機公開金鑰以確認一主機簽章;一方塊,其係架構以由一來源接收認證資料,該認證資料係根據一廢止表列以識別該憑證上之至少一資料為有效或無效的;以及 一方塊,其係架構以避免傳輸一對話金鑰至該主機以建立一安全通信通道,若該等簽章係無效的。
  109. 140
    A computer program product, the computer program product comprising:a signal bearing medium carrying digital information, which can be operated using a firmware, the digital information comprising a program, comprising: a block, the structure of which is A host receives a certificate, the certificate includes a plurality of fields, including a field holding a public key of a certificate signed by a certificate management center;a block, which is structured to confirm the signature on the certificate, the The confirmation action includes: using the public key of the agreement to confirm the signature of the certificate management center;and using a public key of the host on the certificate to confirm a signature of the host;a block that is structured to receive authentication from a source Data, the authentication data is based on a revocation list to identify that at least one piece of data on the certificate is valid or invalid;and a block that is structured to avoid transmitting a session key to the host to establish a secure communication channel, If such signatures are invalid. 140.一種電腦程式產品,該電腦程式產品係包括:承載數位資訊之信號承載媒體,其可利用一韌體以進行操作,該數位資訊係包括程式,其包括:一方塊,其係架構以由一主機接收一憑證,該憑證係包括複數欄位,包括持有一憑證管理中心簽章之一協定公開金鑰之一欄位;一方塊,其係架構以確認該憑證上之簽章,該確認動作係包括:利用該協定公開金鑰以確認該憑證管理中心簽章;以及利用該憑證上之一主機公開金鑰以確認一主機簽章;一方塊,其係架構以由一來源接收認證資料,該認證資料係根據一廢止表列以識別該憑證上之至少一資料為有效或無效的;以及一方塊,其係架構以避免傳輸一對話金鑰至該主機以建立一安全通信通道,若該等簽章係無效的。
  110. 141
    A method of preserving data stored on a medium, the method comprising:attaching content privileges to the media, wherein the privileges are managing multiple levels of access actions;and structuring the media to comply with the content privileges and predetermined conditions Agree to access the content. 141.一種保全媒體上儲存資料之方法,該方法包括:將內容特權附加至該媒體,其中,該等特權係管理複數等級之存取動作;以及架構該媒體以根據該等內容特權及預定條件同意該內容之存取動作。
  111. 142
    The method according to item 141 of the scope of patent application, wherein one of the access actions of the content of the level includes at least playing, copying, and processing the content One of the content. 142.如申請專利範圍第141項所述之方法,其中,該內容之該等等級之存取動作之一至少包括播放、複製、及處理該 內容之一者。
  112. 143
    The method according to item 142 of the scope of patent application, wherein the content copying action includes copying a limited number or an unlimited number of predetermined recording content copies. 143.如申請專利範圍第142項所述之方法,其中,該內容複製動作係包括複製一有限數目、或一無限數目之預定錄製內容複製。
  113. 145
    The method according to item 141 of the scope of patent application, wherein the predetermined conditions include at least:identifying a channel to transmit the content;and checking a revocation list to obtain a The revocation index, in which the existence of the revocation index is used to exclude access. 145.如申請專利範圍第141項所述之方法,其中,該等預定條件係至少包括:鑑別一通道以進行該內容之傳送;以及檢查一廢止表列以,在同意存取前,得到一廢止指標,其中,該廢止指標之存在係用來排除允許存取。
  114. 146
    The method according to item 141 of the scope of patent application, wherein the additional content privileges can be operated using a data management system, wherein the content is stored on the media and the management system is managing the content Access action. 146.如申請專利範圍第141項所述之方法,其中,該等附加內容特權係可利用一資料管理系統以進行操作,其中,該內容係儲存於該媒體上,該管理系統係管理該內容之存取動作。
  115. 149
    The method as described in claim 147, wherein the flexible system includes an application specific integrated circuit (ASIC). 149.如申請專利範圍第147項所述之方法,其中,該韌體係包括在一特殊應用積體電路(ASIC)中。
  116. 150
    The method according to item 146 of the scope of patent application, wherein the data management system uses at least one application programming interface (API) to manage content access actions, and the application programming interface (API) uses a host to restrict Access to the media. 150.如申請專利範圍第146項所述之方法,其中,該資料管理系統係經由至少一應用程式界面(API)以管理內容存取動作,該應用程式界面(API)係利用一主機以限制該媒體之存取動作。
  117. 152
    The method as described in claim 150, wherein the application program interface (API) can only perform access operations through an authentication channel. 152.如申請專利範圍第150項所述之方法,其中,該應用程式界面(API)係僅能夠經由一鑑別通道以進行存取動作。
  118. 153
    The method according to item 141 of the scope of patent application, wherein the media is a portable media, including an optical disc, and the content includes original movie production content, recorded content, copied content, unlocked content , And at least one of the delisted content. 153.如申請專利範圍第141項所述之方法,其中,該媒體係一可攜式媒體,包括一光學碟片,且該內容係包括原版影片製作內容、記錄內容、複製內容、解除鎖定內容、及解除定內容之至少一者。
  119. 155
    The method according to item 154 of the scope of patent application, wherein the media holds at least one of the original movie production content and the recorded content, and the original movie production content and the recorded content are respectively related to a key box, And the key box is connected to the media. 155.如申請專利範圍第154項所述之方法,其中,該媒體係持有原版影片製作內容及記錄內容之至少一者,該原版影片製作內容及該記錄內容分別關連於一金鑰盒子,且該金鑰盒子係連結於該媒體。
  120. 156
    The method according to item 155 of the scope of patent application, wherein the original movie production content and the recorded content, along with its associated key box, respectively provide a complete access system. 156.如申請專利範圍第155項所述之方法,其中,該原版影片製作內容及該記錄內容,伴隨其關連金鑰盒子,係分別提供一完整存取系統。
  121. 157
    The method according to item 155 of the scope of patent application, wherein the key box can be unlinked from a first medium and relinked to a second medium to generate a complete access on the second medium System, which is also linked to the key box. 157.如申請專利範圍第155項所述之方法,其中,該金鑰盒子可以與一第一媒體解除連結、並重新連結至一第二媒體,藉以在該第二媒體上產生一完整存取系統,其同時連結以該金鑰盒子。
  122. 158
    A device for preserving content stored on a medium, the device comprising:at least one tool for transmitting content to the medium, the tool having an access action with multiple levels of structure, wherein content privileges and predetermined conditions manage the Content access action. 158.一種保全媒體上儲存內容之裝置,該裝置包括:至少一工具,用以傳輸內容至該媒體,該工具係架構以附加複數等級之存取動作,其中,內容特權及預定條件係管理該內容之存取動作。
  123. 159
    The device according to item 158 of the scope of patent application, further comprising:a combination lock coupled to the tool. The combination lock is structured to connect a key box to the media. 159.如申請專利範圍第158項所述之裝置,更包括:一密碼鎖,其耦接至該工具,該密碼鎖係架構以將一金鑰盒子連結至該媒體。
  124. 160
    The device according to item 159 of the scope of patent application, further comprising:a special application integrated circuit (ASIC) coupled to the combination lock;and a random key generator embedded with the special application In an integrated circuit (ASIC), the random key generator provides at least one secret key of the medium. 160.如申請專利範圍第159項所述之裝置,更包括:一特殊應用積體電路(ASIC),其耦接至該密碼鎖;以及一隨機金鑰產生器,其內嵌以該特殊應用積體電路(ASIC),該隨機金鑰產生器係至少提供該媒體之一秘密金鑰。
  125. 161
    The device according to item 158 of the scope of patent application, wherein the content privileges include at least one of:playing, copying, and processing the content. 161.如申請專利範圍第158項所述之裝置,其中,該等內容特權係至少包括:播放、複製、處理該內容之一者。
  126. 162
    The device according to item 161 of the scope of patent application, wherein the content privilege of the content copy includes:copying a limited number of specific content copies. 162.如申請專利範圍第161項所述之裝置,其中,內容複製之該內容特權係包括:複製一限定數目之特定內容複製。
  127. 163
    The device according to item 158 of the scope of patent application, wherein the predetermined conditions include at least:identifying a channel to perform the content transmission action;and checking a revocation list to agree to the access action, Obtain a revocation indicator, wherein the existence of the revocation indicator is used to exclude the access permission action. 163.如申請專利範圍第158項所述之裝置,其中,該等預定條件係至少包括:鑑別一通道以進行該內容之傳送動作;以及檢查一廢止表列以,在同意存取動作前,取得一廢止指標,其中,該廢止指標之存在係用來排除允許存取動作。
  128. 164
    The device according to item 158 of the scope of patent application, wherein the additional content privileges can be operated using a data management device, wherein the content is stored on the medium as block data, and the management system is The firmware on the special application integrated circuit (ASIC) is used to manage the block data, so as to avoid content access actions outside the firmware. 164.如申請專利範圍第158項所述之裝置,其中,該等附加內容特權係可利用一資料管理裝置以進行操作,其中,該內容係以方塊資料儲存於該媒體上,該管理系統係經由該特殊應用積體電路(ASIC)上之韌體以管理該方塊資料,藉以避免該韌體外之內容存取動作。
  129. 165
    The device according to item 164 of the scope of patent application, wherein the special application integrated circuit (ASIC) is placed in a controller, and the flexible system on the special application integrated circuit (ASIC) includes at least one A secure application programming interface (API) and an open application programming interface (API), among which:the open application programming interface (API) agrees to access actions of file system data on the media;and the secure application programming interface (API) is According to at least one identification code on the medium, the accessing action of the secured data on the medium is agreed. 165.如申請專利範圍第164項所述之裝置,其中,該特殊應用積體電路(ASIC)係放置於一控制器中,該特殊應用積體電路(ASIC)上之該韌體係至少包括一安全應用程式界面(API)及一開放應用程式界面(API),其中:該開放應用程式界面(API)係同意該媒體上檔案系統資料之存取動作;以及該安全應用程式界面(API)係根據該媒體上之至少一識別碼,藉以同意該媒體上保全資料之存取動作。
  130. 167
    The device according to item 164 of the patent application scope, wherein the flexible system manages content access actions through at least one application programming interface (API), which avoids a host from performing the media. Block-level access. 167.如申請專利範圍第164項所述之裝置,其中,該韌體係經由至少一應用程式界面(API)以管理內容存取動作,該應用程式界面(API)係避免一主機進行該媒體之方塊等級存取。
  131. 168
    The device according to item 167 of the scope of patent application, wherein the application program interface (API) prevents a host from performing block-level access to the content. 168.如申請專利範圍第167項所述之裝置,其中,該應用程式界面(API)係避免一主機進行該內容之方塊等級存取。
  132. 169
    The device according to item 167 of the scope of patent application, wherein the application program interface (API) is capable of accessing only through an authentication channel. 169.如申請專利範圍第167項所述之裝置,其中,該應用程式界面(API)係僅能夠經由一鑑別通道進行存取動作。
  133. 170
    The device according to item 158 of the scope of patent application, wherein the media is a portable media, including an optical disc, and the content includes the original film making content, recording content, copying content, and unlocking content , And at least one of the delisted content. 170.如申請專利範圍第158項所述之裝置,其中,該媒體係一可攜式媒體,包括一光學碟片,且該內容係包括原版影片製作內容、記錄內容、複製內容、解除鎖定內容、及解除定內容之至少一者。
  134. 171
    The device described in claim 165, wherein the identification code provides a seed of a key box, and the key box provides a key for at least one of unlocking content and decrypting content. 171.如申請專利範圍第165項所述之裝置,其中,該識別碼係提供一金鑰盒子之一種子,該金鑰盒子係提供解除鎖定內容及解密內容之至少一者之金鑰。
  135. 172
    The device according to item 171 of the scope of patent application, wherein the media holds at least one of the original film production content and the recorded content, and the original film The film production content and the recorded content, along with its associated key box, provide a complete access system, respectively. 172.如申請專利範圍第171項所述之裝置,其中,該媒體係持有原版影片製作內容及記錄內容之至少一者,該原版影 片製作內容及該記錄內容,伴隨其關連金鑰盒子,係分別提供一完整存取系統。
  136. 173
    The device according to item 171 of the scope of patent application, wherein the key box can be unlinked from a first medium and re-linked to a second medium to generate a complete access on the second medium System, which is also linked to the key box. 173.如申請專利範圍第171項所述之裝置,其中,該金鑰盒子可以與一第一媒體解除連結、並重新連結至一第二媒體,藉以在該第二媒體上產生一完整存取系統,其同時連結以該金鑰盒子。
  137. 174
    A method for preserving pre-recorded content of an original film production, comprising:encrypting the pre-recorded content;and connecting a key box and at least one identification code to a media disc, the key box is structured to use the The identification code of the key box, wherein the identification codes include at least one of a complete identification code and a part of the identification code, and the part of the identification code is required to be completed through a primary transaction before using the key box. 174.一種原版影片製作保全預先錄製內容之方法,其包括:加密該預先記錄內容;以及連接一金鑰盒子及至少一識別碼至一媒體碟片,該金鑰盒子係架構以使用具有該金鑰盒子之該識別碼,其中,該等識別碼係包括一完整識別碼及一部分識別碼之至少一者,該部分識別碼係要求,在使用該金鑰盒子前,經由一次要交易完成。
  138. 175
    The method as described in claim 174, wherein the key box is structured to provide a key for operating a triple-DES block, and the triple-DES ) The block receives the output of one of the random key generators. The random key generator uses the complete identification code of the media disc for seeding. The triple-DES standard block uses the The complete identification code of the key box is used to decrypt and encrypt the content. 175.如申請專利範圍第174項所述之方法,其中,該金鑰盒子係架構以提供操作一三重資料加密標準(triple-DES)方塊之金鑰,該三重資料加密標準(triple-DES)方塊係接收一隨機金鑰產生器之一輸出,該隨機金鑰產生器係利用該媒體碟片之該完整識別碼以進行播種,該三重資料加密標準(triple-DES)方塊係使用具有該金鑰盒子之該完整識別碼,藉以對該內容進行解密及加密動作。
  139. 176
    The method according to item 174 of the scope of patent application, wherein the identification codes include public and private identification codes. 176.如申請專利範圍第174項所述之方法,其中,該等識別碼係包括公開及私密識別碼。
Independent claims139