WO02052780A1

Information processing system and method

Abstract

An information processing system and method for realizing efficient processing using an enabling key block (EKB) using a categorized tree structure. An EKB composed of encrypting data for encrypting an upper-order key by using a lower-order key on a selection path of a key tree having sub-trees managed by a category entity is created and provided to a device. When a request to create an EKB is made, a structure for creating a route key by itself or a structure for requesting a key distribution center to create a route key is selectively executed. Further a structure for requesting a category entity to create a sub-EKB when the EKB distribution center creates an EKB is provided, and therefore the EKB creation and management are made efficient.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

50 claims: 48 independent, 2 dependent

  1. 1
    The range 1 of a claim. From the route of Rie which constituted a plurality of devices as a leaf to a leaf Route on a path, It is a style about a node and the key tree which matched the key with the leaf respectively. It accomplishes, Higher rank choose the path which constitutes the 1 Tree, and according to low rank 1 on a selection path It has one encryption processing De evening of a key, Node tree 1 Set corresponding to the above-mentioned selection path It is a profit about A. It is an information processing system with the composition which provides a device with validation key block (EKB) whose decoding was enabled only in the device in which for is possible, As opposed to 1 issue center (KD C) which generates validation key block (EKB) EKB requester which requires generation of The EKB, The 1st E KB generation demand as a E KB generation demand containing a generated Le 1 smallness key, or the roux in key issue center (KD C) -- a crested ibis -- 1 generation and the generation route key E KB generation demand of The 2 which requires the E KB generation to include, as a E K B generation demand of as opposed to key issue center 1 (KD C) for whether it is Either -- output it carries out -- a key issue center (KD C) and E KB generation demand of above-mentioned The 1, responding to reception of or a E KB generation demand of above-mentioned The 2 -- a receiving roux -- crested ibis 1 or a generation roux -- the information Treatment system having the composition which performs E KB generation including crested ibis 1. 請求の範囲 1. 複数のデバイスをリーフとして構成したッリーのルートからリーフまでの パス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーツリーを構 成し、 該キ一ヅリーを構成するパスを選択して選択パス上の下位キ一による上位 キーの暗号化処理デ一夕を有し、 前記選択パスに対応するノードキ一セッ トを利 用可能なデバイスにおいてのみ復号可能とした有効化キーブロック (EKB) を デバイスに提供する構成を持つ情報処理システムであり、 有効化キーブロック (EKB) を生成するキ一発行センター (KD C) に対し て EKBの生成を要求する EKBリクエスタは、 生成済みル一小キーを含む E KB生成要求としての第 1の E KB生成要求、 ま たは、 キー発行センター (KD C) におけるルートキ一生成および該生成ルートキー を含む E KB生成を要求する第 2の E KB生成要求、 のいずれかをキー発行センタ一 (KD C) に対する E K B生成要求として出力 し、 キー発行センター (KD C) は、 前記第 1の E KB生成要求、 または前記第 2 の E KB生成要求の受信に応じて受信ルートキ一または生成ルートキ一を含めた E KB生成を実行する構成を有することを特徴とする情報処瑪システム。
  2. 3
    Said E KB requester, a memory measure, or Netsai on Network which can be perused The EKB evening acquired from A It is the feature about it being the composition which chooses a E KB type identifier based on a A definition list. Information processing system given in Claim 2 to carry out. 3. 前記 E KBリクエスタは、 記憶手段、 または、 ネッ トワーク上の閲覧可能サイ トから取得される EKB夕 ィプ定義リストに基づいて E KBタイプ識別子を選択する構成であることを特徴 とする請求項 2に記載の情報処理システム。
  3. 4
    Discernment De of category Tree which said E KB type definition list can E KB process It is the feature about their being one evening and node I D which is the identifiers of the node of Category 1. Information processing system given in Claim 2 to carry out. 4. 前記 E KBタイプ定義リストの E KB処理可能なカテゴリヅリーの識別デ 一夕は、 カテゴリヅリ一のノードの識別子であるノード I Dであることを特徴と する請求項 2に記載の情報処理システム。
  4. 5
    It is Seki to the device which belongs to said EKB type definition list at a category tree. Information processing system given in Claim 2 being composition including the explanation to give 5. 前記 EKBタイプ定義リストには、 カテゴリツリーに属するデバイスに関 する説明を含む構成であることを特徴とする請求項 2に記載の情報処理システム
  5. 6
    From the route of Tree which constituted a plurality of Depice as a leaf to a leaf Route on a path, Node, It is a style about 1 Tree which reached and matched a key with a leaf respectively. It accomplishes, A path which constitutes the Key ring 1 is chosen and it is on a selection path. Higher rank by C low rank 1 ' It has encryption processed data of a key, Node Keyset corresponding to the above-mentioned selection path It is a profit about A. Validation key pro who made decoding possible only in Depice in which for is possible Dug (EKB) It is an information processing system with composition with which a device is provided, Above-mentioned Key ring 1, It is classified based on a category, Category To 'entity It is the composition which carries out two or more owners of the category Tree as Sub tree therefore managed. 1 block of validation (EKB) Key issue center to generate (KD C) Is E It is a demand entity of KB generation. Validation based on a demand of the E KB Request evening Keeping lock (EKB) In generation, Validation key block to generate. (EKB) Category Tree which can be decoded is managed. One or more categories It is each power to - Endy. In a Age tree, he is a substitute who can process. A generation demand of E KB is outputted, Category. Sub validation key block received from * Entity (substitute EKB) It is based. It can process in one or more Category 1. It is Special about having the composition which generates E KB. Information processing system considered as a mark. 6. 複数のデパイスをリーフとして構成したヅリーのルートからリーフまでの パス上のルート、 ノード、 およびリーフに各々キーを対応付けたキ一ヅリーを構 成し、 該キーヅリ一を構成するパスを選択して選択パス上 C 下位キ一による上位 ' キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを利 用可能なデパイスにおいてのみ復号可能とした有効化キープロ ヅク (EKB) を デバイスに提供する構成を持つ情報処理システムであり、 前記キーヅリ一は、 カテゴリに基づいて区分され、 カテゴリ 'エンティティに よって管理されるサブッリーとしてのカテゴリヅリーを複数有する構成であり、 有効化キ一ブロック (EKB) を生成するキー発行センター (KD C) は、 E KB生成の要求エンティティである E KBリクエス夕の要求に基づく有効化 キープロック (EKB) の生成において、 生成する有効化キーブロック (EKB) の復号可能なカテゴリヅリーを管理する 1以上のカテゴリ ·エンディティに各力 テゴリツリーにおいて処理可能なサブ E KBの生成要求を出力し、 カテゴリ * ェ ンティティから受領したサブ有効化キーブロック (サブ EKB) に基づいて 1以 上のカテゴリヅリ一において処理可能な E KBを生成する構成を有することを特 徴とする情報処理システム。
  6. 8
    Kate who received the sub EKB generation demand from the above-mentioned key issue center (KD C) Gori and entity, It is based on the key matched with The node belonging to the category tree of self to manage, or Li - Off, and is a sub validation key block as E KB which can be processed. (substitute EKB) It indicates to Claim 6 being the composition to generate. Information processing system. 8. 前記キー発行センター (KD C) からサブ EKB生成要求を受領したカテ ゴリ ·エンティティは、 自己の管理するカテゴリツリーに属するノードまたはリ ーフに対応付けられたキーに基づいて処理可能な E KBとしてのサブ有効化キー ブロック (サブ EKB) を生成する構成であることを特徴とする請求項 6に記載 の情報処理システム。
  7. 9
    two or more steps of route Tree are constituted by the above-mentioned 1 Tree and the highest rung -- the route It links with A dragon 1 directly. Tap level and category Tree, the Tap level Category it is constituted by subcategory Tree connected with Li's 1 lower berth -- the above-mentioned category and Entity, Pipe science and engineering of above-mentioned top-level and Category It carries out and he is the Tap level Category Lolli 1 and the top-level . Kate. Subcategory Tree which stands in a row in the lower berth of Gori lily is managed, The above-mentioned category' Li entity, Self manages. Top-level and Category Lolli 1 and the A To subCategory Lolli which stands in a row in the lower berth of Level and Category Lolli 1 It corresponds to the node or leaf which belongs. It is based on the key set up and is a sub validation key block as E K B which can be processed. (substitute EKB) It is the composition to generate. Information processing system given in Claim 6 by which it is characterized. 9. 前記キ一ヅリーは、 最上段に複数段のルートヅリーが構成され、 該ルート ヅリ一に直結する ト ヅプレベル · カテゴリヅリー、 該トヅプレベル · カテゴリヅ リ一の下段に連結されるサブカテゴリヅリーによって構成され、 前記カテゴリ · ェンティティは、 前記トップレベル · カテゴリッリーの管理工 ンティティ として該トヅプレベル · カテゴリッリ一および該トップレベル . カテ ゴリヅリーの下段に連なるサブカテゴリヅリーの管理を行ない、 前記カテゴ 'リ ·エンティティは、 自己の管理する トップレベル · カテゴリッリ 一および該ト ヅプレベル · カテゴリッリ一の下段に連なるサブカテゴリッリーに 属するノードまたはリーフに対応して設定されるキーに基づいて処理可能な E K Bとしてのサブ有効化キーブロック (サブ EKB) を生成する構成であることを 特徴とする請求項 6に記載の情報処理システム。
  8. 10
    1 0. From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on a path, It is a pair about a key respectively to a node and a leaf. Attached Key ring 1 It constitutes, the path which constitutes the 1 Tree is chosen, and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Kisera corresponding to the above-mentioned selection path A 1 block of validation whose decoding was enabled only in the device which can be used (epsilonkappabeta) It is an information processing method in a system with the composition with which a device is provided, Validation key block (epsilonkappabeta) As opposed to key issue center 1 (KD C) to generate E KB requester which requires generation of The E KB, The E KB generation demand of The 1 as a E KB generation demand containing a generated route key, Or the route key generation in key issue center 1 (KD C) and the generation route key E KB generation demand of The 2 which requires the E KB generation to include, as a E KB generation demand of as opposed to key issue center (KD C) for whether it is Either -- output it carries out -- key issue center (KD C) and EKB generation demand of above-mentioned The 1, An information processing method performing E KB generation which includes a receiving route key or a generation route key according to reception of or a E KB generation demand of above-mentioned The 2. 1 0. 複数のデバイスをリーフとして構成したヅリーのルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対 付けたキーヅリ一を 構成し、 該キ一ヅリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセヅ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キ一ブロック (ΕΚΒ) をデバイスに提供する構成を持つシステムにおける情報処理方法であり、 有効化キーブロック (ΕΚΒ) を生成するキー発行センタ一 (KD C) に対し て E KBの生成を要求する E KBリクエスタは、 生成済みルートキーを含む E KB生成要求としての第 1の E KB生成要求、 ま たは、 キー発行センタ一 (KD C) におけるルートキー生成および該生成ルートキー を含む E KB生成を要求する第 2の E KB生成要求、 のいずれかをキー発行センター (KD C) に対する E KB生成要求として出力 し、 キー発行センター (KD C) は、 前記第 1の EKB生成要求、 または前記第 2 の E KB生成要求の受信に応じて受信ルートキーまたは生成ルートキーを含めた E KB生成を実行することを特徴とする情報処理方法。
  9. 11
    1 1. it is Classified Based on the Above-mentioned 1 Tree and Category -- Category Enti Composition Which Carries Out Two or More Owners of Category 1 as SubTree Managed with Tee There, The above-mentioned EKB requester chooses a E KB type identifier based on the E KB type definition list which matched the E KB type identifier and one discernment De evening of category Tree in which E KB processing is possible, It is [ the E KB generation demand of said The 1, or ] a front about the E KB generation demand containing a selection E KB type identifier. It is Output to said key issue center (KD C) as an EKB generation demand of account The 2. Claim 1 characterized by To Information processing method given in 0. 1 1. 前記キ一ヅリーは、 カテゴリに基づいて区分され、 カテゴリ · ェンティ ティによって管理されるサブヅリーとしてのカテゴリヅリ一を複数有する構成で あり、 前記 EKBリクエスタは、 E KBタイプ識別子と、 E KB処理可能なカテゴリヅリーの識別デ一夕とを対 応付けた E KBタイプ定義リストに基づいて E KBタイプ識別子を選択し、 選択 E KBタイプ識別子を含む E KB生成要求を前記第 1の E KB生成要求または前 記第 2の EKB生成要求として前記キー発行センター (KD C) に対して出力す ることを特徴とする請求項 1 0に記載の情報処理方法。
  10. 12
    The above-mentioned E KB requester, a memory measure, or Netsai on Network which can be perused The EKB evening acquired from A Claim choosing a E KB type identifier based on a A definition list Paragraph 1 Information processing method given in 1. 12. 前記 E KBリクエスタは、 記憶手段、 または、 ネッ トワーク上の閲覧可能サイ トから取得される EKB夕 ィプ定義リストに基づいて E KBタイプ識別子を選択することを特徴とする請求 項 1 1に記載の情報処理方法。
  11. 13
    1 3. Discernment of category Tree which said E KB type definition list can E KB process It is the feature about their being data and node I D which is the identifiers of the node of category Tree. Claim 1 to carry out Information processing method given in 1. 1 3. 前記 E KBタイプ定義リストの E KB処理可能なカテゴリヅリーの識別 データは、 カテゴリヅリーのノードの識別子であるノード I Dであることを特徴 とする請求項 1 1に記載の情報処理方法。
  12. 14
    To the device which belongs to said E KB type definition list at a category tree Claim 1 being composition including the related explanation Information processing method given in 1. 14. 前記 E KBタイプ定義リストには、 カテゴリツリーに属するデバイスに 関する説明を含む構成であることを特徴とする請求項 1 1に記載の情報処理方法。
  13. 15
    1 5. From Le 1 A of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Route on a path, - Do, And key tree which matched a key with a leaf respectively It constitutes, a path which constitutes the key Tree is chosen and it is based on a low rank key on a selection path -- the upper -- , about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A Validation 1 Plock whose decoding was enabled only in a device which can be used (EKB) It is an information processing method in a system with composition with which a device is provided, The above-mentioned key tree, It is classified based on a category, Category ' To an entity It is the composition which carries out two or more owners of the category Tree as subTree therefore managed. validation key block (EKB) Key issue center to generate (KD C) Is E It is a demand entity of KB generation. Validation based on a demand of a E KB requester Key block (EKB) In generation, Validation key block to generate. (EKB) Category 1 which can be decoded is managed. One or more categories It is each power to - entity. In a Age tree, he is a substitute who can process. A generation demand of EKB is outputted, Category. Sub validation key block received from 'Entity (sub EKB) It is based. It can process in one or more Category 1. Information generating E KB Disposal method. 1 5. 複数のデバイスをリーフとして構成したヅリ一のル一トからリーフまで のパス上のルート、 ード、 およびリーフに各々キーを対応付けたキーツリーを 構成し、 該キーヅリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キ一プロック (EKB) をデバイスに提供する構成を持つシステムにおける情報処理方法であり、 前記キーツリーは、 カテゴリに基づいて区分され、 カテゴリ ' エンティティに よって管理されるサブヅリーとしてのカテゴリヅリーを複数有する構成であり、 有効化キーブロック (EKB) を生成するキー発行センター (KD C) は、 E KB生成の要求エンティティである E KBリクエスタの要求に基づく有効化 キーブロック (EKB) の生成において、 生成する有効化キーブロック (EKB) の復号可能なカテゴリヅリ一を管理する 1以上のカテゴリ · エンティティに各力 テゴリツリーにおいて処理可能なサブ E KBの生成要求を出力し、 カテゴリ ' ェ ンティティから受領したサブ有効化キーブロック (サブ EKB) に基づいて 1以 上のカテゴリヅリ一において処理可能な E KBを生成することを特徴とする情報 処理方法。
  14. 16
    1 6. Above-mentioned Key Issue Center (KD C) E It is a pair about KB type identifier and the identification data of Category Lolli in which E KB processing is possible. It has a beam E KB type definition list with Response, E entity which requires generation of KB it is -- E KB type included during the E KB generation demand received from a E KB requester the search of a E K B type definition list based on an identifier -- discernment day of Category 1 Extract the evening. One or more Kate corresponding to the identification data of extracted category Lily Gori . It is based on substitute E KB whom the entity generated, E KB type definition squirrel Composition which generates and provides with E KB usable in common Category 1 set as A it is -- Claim 1 characterized by things Information processing method given in 5. 1 6. 前記キー発行センター (KD C) は、 E KBタイプ識別子と、 E KB処理可能なカテゴリッリーの識別データとを対 応付けた E KBタイプ定義リストを有し、 E KBの生成を要求するエンティティ である E KBリクエスタから受領する E KB生成要求中に含まれる E KBタイプ 識別子に基づく E K Bタイプ定義リストの検索によりカテゴリヅリ一の識別デー 夕を抽出して、 抽出されたカテゴリヅリーの識別データに対応する 1以上のカテ ゴリ . エンティティの生成したサブ E KBに基づいて、 E KBタイプ定義リス ト に設定されたカテゴリヅリ一に共通に使用可能な E KBを生成して提供する構成 であることを特徴とする請求項 1 5に記載の情報処理方法。
  15. 17
    1 7. Power Which Received Sub E KB Generation Demand from Above-mentioned Key Issue Center (KD C) Age and Entity, the node belonging to category Tree of self to manage -- or -- being based on the key matched with the leaf -- sub validation as EKB which can be processed 1 block (substitute EKB) Generating Claim 1 Information given in 5 Disposal method. 1 7. 前記キー発行センター (KD C) からサブ E KB生成要求を受領した力 テゴリ ·エンティティは、 自己の管理するカテゴリヅリーに属するノードまたは リーフに対応付けられたキーに基づいて処理可能な EKBとしてのサブ有効化キ 一ブロック (サブ EKB) を生成することを特徴とする請求項 1 5に記載の情報 処理方法。
  16. 18
    1 8. Two or More Steps of Route Trees are Constituted by Above-mentioned Key ring 1 and Highest Rung, The roux It links with Tori 1 directly. A Tap level' category tree and the Tap level - Category It is constituted by subcategory Tree connected with the lower berth of Rie, Pipe science and engineering of the above-mentioned category 'entity and above-mentioned top level' category Tree They are Category 1 and top-level 'top level' Kate as Entity. SubCategory 1 which stands in a row in the lower berth of Gorelli 1 is managed, The above-mentioned category and entity, self--- Tap level Category which 3 manages Subcategory Tree which stands in a row in the lower berth of 1, and the Tap level and Category Lolli Correspond to the node or leaf which belongs. It is based on the key set up and is a sub validation key block as E K B which can be processed. (substitute EKB) It generates. Claim 1 Information processing method given in 5. 1 8. 前記キーヅリ一は、 最上段に複数段のルートツリーが構成され、 該ルー トヅリ一に直結する ト ヅプレベル ' カテゴリツリー、 該トヅプレベル · カテゴリ ッリーの下段に連結されるサブカテゴリヅリーによって構成され、 前記カテゴリ ' エンティティは、 前記トップレベル ' カテゴリヅリーの管理工 ンティティとして該トップレベル ' カテゴリヅリ一および該トップレベル ' カテ ゴリッリ一の下段に連なるサブカテゴリヅリ一の管理を行ない、 前記カテゴリ ·エンティティは、 自 3の管理するトヅプレベル · カテゴリヅリ 一および該トヅプレベル · カテゴリッリーの下段に連なるサブカテゴリヅリーに 属するノードまたはリーフに対応して設定されるキーに基づいて処理可能な E K Bとしてのサブ有効化キーブロック (サブ EKB) を生成することを特徴とする 請求項 1 5に記載の情報処理方法。
  17. 19
    1 9. From the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Route on a path, A node and key tree which matched the key with the leaf respectively It constitutes, the path which constitutes the key tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A Set to the device which can be used. Computer - which makes the information processing in a system with the composition which provides Depice with validation key block (E K B) which accepted, and whose decoding it enabled perform on computer and a system Program record intermediation which recorded the program It is the body, Above-mentioned computer and program, and the E K B generation demand of The 1 as a E K B generation demand containing a generated route key, Or the route key generation in key issue center (K D C) and the generation route One E K B generation of the E K B generation demands of The 2 which requires the E K B generation containing a key Step which receives a demand, E K B generation which includes a receiving route key according to the kind of received E K B generation demand, or a roux -- either of the E K B generation including generation of crested ibis 1, and a generation route key Program recording medium having a step which performs processing alternatively. 1 9. 複数のデバイスをリーフとして構成したヅリ一のルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーツリーを 構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック ( E K B ) をデパイスに提供する構成を持つシステムにおける情報処理をコンピュータ · シ ステム上で実行せしめるコンピュータ · プログラムを記録したプログラム記録媒 体であって、 前記コンピュータ · プログラムは、 生成済みルートキーを含む E K B生成要求としての第 1の E K B生成要求、 ま たは、 キー発行センター (K D C ) におけるルートキー生成および該生成ルート キーを含む E K B生成を要求する第 2の E K B生成要求のいずれかの E K B生成 要求を受信するステップと、 受信した E K B生成要求の種類に応じて、受信ルートキーを含めた E K B生成、 またはルートキ一の生成および生成ルートキーを含めた E K B生成のいずれかの 処理を選択的に実行するステップと、 を有することを特徴とするプログラム記録媒体。
  18. 20
    2 0 . From the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Route on a path, A node and key tree which matched 1 with the leaf respectively It constitutes, the path which constitutes the key Tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A Set to the device which can be used. Computer - which makes the information processing in a system with the composition which provides a device with validation key block (E K B) which accepted, and whose decoding it enabled perform on computer and a system Program record intermediation which recorded the program It is the body, Above-mentioned computer and program are based on the E K B type identifier contained in a E K B generation demand, and is E K B type discernment. Child, E The step which extracts one discernment De evening of Category Lolli from the E K B type definition list which matched the identification data of one or more category trees in which K B processing is possible, setting at each category Tree to one or more category entities which manage category Tree corresponding to the identification data of Category 1 of which extraction was done -- the substitute who can process -- an owner -- The step which outputs the generation demand of effect-ized key block (substitute E K B), and category, Sub validation key block received from 'entity (substitute EKB) Steps which is based and generates E KB which can be processed in one or more category Tree Program recording medium having A. 2 0 . 複数のデバイスをリーフとして構成したヅリ一のルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キ一を対応付けたキーツリーを 構成し、 該キーヅリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック (E K B ) をデバイスに提供する構成を持つシステムにおける情報処理をコンピュータ · シ ステム上で実行せしめるコンピュータ · プログラムを記録したプログラム記録媒 体であって、 前記コンピュータ · プログラムは、 E K B生成要求に含まれる E K Bタイプ識別子に基づいて、 E K Bタイプ識別 子と、 E K B処理可能な 1以上のカテゴリツリーの識別データとを対応付けた E K Bタイプ定義リストからカテゴリッリーの識別デ一夕を抽出するステップと、 抽出されたカテゴリヅリ一の識別データに対応するカテゴリヅリーを管理する 1以上のカテゴリ · エンティティに各カテゴリヅリーにおいて処理可能なサブ有 効化キーブロック (サブ E K B ) の生成要求を出力するステップと、 カテゴリ、, ' エンティティから受領したサブ有効化キーブロック (サブ EKB) に基づいて 1以上のカテゴリヅリーにおいて処理可能な E KBを生成するステヅ プと、 を有することを特徴とするプログラム記録媒体。
  19. 21
    2 1. From Route of A tree 1 Which Constituted a Plurality of Devices as Leaf to Leaf Route on Path, Key ring 1 which matched the key with the node and the leaf respectively It constitutes, the path which constitutes the Keatuli 1 is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Kisera corresponding to the above-mentioned selection path A It is an information processing system with the composition which provides Depice with validation key block (EKB) whose decoding was enabled only in the device which can be used, It decodes in each of Subtitled 1 set up as partial Tree of the above-mentioned validation key block (EKB) and above-mentioned Keatuli 1. It is constituted as composition E KB of sub validation keeping mouth A (substitute E KB) which can be processed, De 1 taffy 1 Le of fixed length [ each / of a plurality of key and one De evenings contained in the composition E KB ] Information processing system having the composition stored in Do. 2 1. 複数のデバイスをリーフとして構成したッリ一のルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーヅリ一を 構成し、 該キーツリ一を構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセヅ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック (EKB) をデパイスに提供する構成を持つ情報処理システムであり、 前記有効化キーブロック (EKB) は、 前記キーツリ一の部分ヅリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キープ口ック (サブ E KB)の合成 E KBとして構成され、 該合成 E KB内に含まれる複数のキー ·デ一夕の各々が固定長のデ一タフィ一ル ド内に格納された構成を有することを特徴とする情報処理システム。
  20. 22
    The above-mentioned subtree, It is classified based on a category, Category 'Enti It is Category Lolli 1 managed with a tee. the above-mentioned sub validation key block (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to category Tree which is set and self manages. , -- it can process based on a Was done key It is generated as E K B. In key issue center 1 (KD C) Said category. 'entity generates. It was substitute Based on E K B, it is usable common to a plurality of category Tree. It is referred to as E K B. Composition of The Claim being adapted to generate E KB Information given in 2 1 Processing system. 22. 前記サブツリーは、 カテゴリに基づいて区分され、 カテゴリ 'ェンティ ティによつて管理されるカテゴリッリ一であり、 前記サブ有効化キーブロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリヅリーに属するノードまたはリーフに対応付け られたキーに基づいて処理可能な E K Bとして生成され、 キー発行センタ一 (KD C) において、 前記カテゴリ ' エンティティの生成し たサブ E K Bに基づいて、 複数のカテゴリヅリーに共通に使用可能な E K Bとし ての合成 E KBを生成する構成であることを特徴とする請求項 2 1に記載の情報 処理システム。
  21. 23
    The above-mentioned sub validation key block (substitute EKB) Each, respectively -- original Al Sub validation key block with Gorism and original key' data length (substitute EKB) As -- it is constituted -- key issue Seng evening 1 (K D C) In the generation processing of composition E K B based on the above-mentioned substitute E K B, It is Construct about composition E K B. Each of the key . data in To substitute E K B is stored in a fixed-length data field. Claim 2 being the composition of performing processing Information processing system given in 1. 23. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキー 'データ長を持つサブ有効化キーブロック (サブ EKB) として構成され、 キー発行セン夕一 (K D C ) は、 前記サブ E K Bに基づく合成 E K Bの生成処理において、 合成 E K Bを構成す るサブ E K B内のキー .データの各々を固定長のデータフィールド内に格納する 処理を実行する構成であることを特徴とする請求項 2 1に記載の情報処理システ ム。
  22. 24
    2 4 . It is Low Rank A about Node Key Set Up corresponding to Each Node Which Constitutes the Above-mentioned Composition E K B and Above-mentioned Key ring 1. Cryptographic Key Data Enciphered Using 1 Do key or Low Rank Leaf Key, one or more node positions of each one encryption Kee de evening stored in said composition E K B -- lower -- Tag in which the existence of the node of the right-and-left position of an about or the cryptographic key data of a leaf position is shown Claim 2 being the composition to include Information processing system given in 1. 2 4 . 前記合成 E K Bは、 前記キーヅリ一を構成する各ノードに対応して設定されるノードキーを下位ノ 一ドキーまたは下位リーフキーを用いて暗号化した暗号化キーデータと、 前記合成 E K Bに格納された 1以上の暗号化キーデ一夕各々のノード位置の下 位の左右位置のノードまたはリーフ位置の暗号化キーデータの有無を示すタグを 含む構成であることを特徴とする請求項 2 1に記載の情報処理システム。
  23. 25
    2 5 . The Above-mentioned Composition E K B the end node or leaf which can decode the composition E K B was used as the lowest stage -- it simplified Choose the path which constitutes Tree and omit an unnecessary node. It is reconstructed. Let the key corresponding to the node or leaf of reconstruction hierarchy Tree be one encryption Kee de evening. Claim 2 carrying out Have Information processing system given in 1. 2 5 . 前記合成 E K Bは、 該合成 E K Bを復号可能な末端ノードまたはリーフを最下段とした簡略化した ヅリーを構成するパスを選択して不要ノードを省略することにより再構築される 再構築階層ヅリーのノードまたはリーフに対応するキーを暗号化キーデ一夕とし て有することを特徴とする請求項 2 1に記載の情報処理システム。
  24. 26
    2 6 . It is key Tree about a plurality of cryptographic key data contained in each of said composition E K B and a plurality of substitutes E K B. It has the composition which re-arranged and was generated according to the node which can be set, or the leaf position. Claim 2 by which it is characterized Information processing system given in 1. 2 6 . 前記合成 E K Bは、 複数のサブ E K Bの各々に含まれる複数の暗号化キーデータを、 キーヅリーに おけるノードまたはリーフ位置に応じて再配列して生成された構成を有すること を特徴とする請求項 2 1に記載の情報処理システム。
  25. 27
    2 7 . To Category Tree as SubTree Classified Based on Category Configuration is Carried Out, From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on the path of until, A node and 1 A dragon which matched the key with the leaf respectively 1 is constituted, The path which constitutes the key tree is chosen and it is to the low rank key on a selection path. At least a To top has encryption processed data of a key, Node Kisera corresponding to the above-mentioned selection path It is the information recording medium which stored validation 1 Plock (E K B) whose decoding was enabled only in the device which can use A, It decodes in each of Sabilli 1 set up as partial Tree of above-mentioned Keatuli 1. Sub validation key block which can be processed (substitute EKB) Composition E KB is stored, This Synthesis Inside of the one De evening field of fixed length [ each / of a plurality of key data contained in Formation E KB ] Information recording medium having the stored composition. 2 7 . カテゴリに基づいて区分されたサブヅリーとしてのカテゴリツリーによ り構成され、 複数のデバイスをリーフとして構成したヅリーのルートからリーフ までのパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキ一ヅリ 一を構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによ る上位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセヅ トを利用可能なデバイスにおいてのみ復号可能とした有効化キ一プロック (E K B) を格納した情報記録媒体であり、 前記キーツリ一の部分ヅリーとして設定されるサブッリ一の各々において復号 処理可能なサブ有効化キーブロック (サブ EKB) の合成 E KBを格納し、 該合 成 E KB内に含まれる複数のキー ·データの各々が固定長のデ一夕フィールド内 に格納された構成を有することを特徴とする情報記録媒体。
  26. 28
    The above-mentioned sub validation key block (substitute EKB) Each, respectively -- original Al Gorism and 1 block of sub validation with original 1' data length (substitute EKB) As -- it is constituted -- the storing field of key and data is the composition made into fixed length Information recording medium given in Claim 27 by which it is characterized. 28. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキ一 'データ長を持つサブ有効化キ一ブロック (サブ EKB) として構成され、 キー ·データの格納領域が固定長とされている構成であること を特徴とする請求項 27に記載の情報記録媒体。
  27. 29
    From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on a path, Key ring 1 which matched the key with the node and the leaf respectively It constitutes, the path which constitutes the key tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node key set corresponding to the above-mentioned selection path It is an information processing method in a system with the composition which provides a device with validation keeping mouth A (EKB) whose decoding was enabled only in the device which can be used, It decodes in each of Subtitled 1 set up as partial Tree of the above-mentioned validation key block (EKB) and above-mentioned Key ring 1. It is constituted as composition EKB of sub validation 1 Prozek (substitute E KB) which can be processed, Day taffy 1 Le of fixed length [ each / of a plurality of key and one De evenings contained in the composition E KB ] Information processing method being stored in Do and providing for a device. 29. 複数のデバイスをリーフとして構成したヅリーのルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーヅリ一を 構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセットを 利用可能なデバイスにおいてのみ復号可能とした有効化キープ口ック (EKB) をデバイスに提供する構成を持つシステムにおける情報処理方法であり、 前記有効化キーブロック (EKB) は、 前記キーヅリ一の部分ヅリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キ一プロヅク (サブ E KB)の合成 EKBとして構成され、 該合成 E KB内に含まれる複数のキー ·デ一夕の各々が固定長のデータフィ一ル ド内に格納されてデバイスに提供することを特徴とする情報処理方法。
  28. 30
    3 0. The above-mentioned subtree, It is classified based on a category, Category - Enti It is category Tree managed with a tee. the above-mentioned sub validation keeping lock (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to Category 1 which is set and self manages. , -- it can process based on a Was done key It is generated as EKB. Key issue center (KD C) Set. Said category. 'entity generates. It was substitute Based on E KB, it is usable common to a plurality of Category Lolli. It is referred to as E KB. Composition of The Claim generating E KB Information processing method given in 29. 3 0. 前記サブツリーは、 カテゴリに基づいて区分され、 カテゴリ ·ェンティ ティによって管理されるカテゴリヅリーであり、 前記サブ有効化キープロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリヅリ一に属するノードまたはリーフに対応付け られたキーに基づいて処理可能な EKBとして生成され、 キー発行センター (KD C) において、 前記カテゴリ ' エンティティの生成し たサブ E KBに基づいて、 複数のカテゴリッリーに共通に使用可能な E KBとし ての合成 E KBを生成することを特徴とする請求項 29に記載の情報処理方法。
  29. 31
    3 1. Above-mentioned Sub Validation Key Block (Substitute EKB) Each, respectively -- original Al Gorism and 1 block of sub validation with original one key' De evening length (substitute EKB) As -- it is constituted -- key issue center (KD C) it sets to the generation processing of composition E KB based on said substitute E KB -- composition E KB -- Construct Each of key and data in To substitute EKB is stored in fixed-length De 1 taffy 1 Rudo. Information processing method given in Claim 29 performing processing. 3 1. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキー ' デ一夕長を持つサブ有効化キ一ブロック (サブ EKB) として構成され、 キー発行センター (KD C) は、 前記サブ E KBに基づく合成 E KBの生成処理において、 合成 E KBを構成す るサブ EKB内のキー · データの各々を固定長のデ一タフィ一ルド内に格納する 処理を実行することを特徴とする請求項 29に記載の情報処理方法。
  30. 32
    It is low rank A about the node key set up corresponding to each node which constitutes above-mentioned validation 1block (EKB) and above-mentioned Keatuli 1. Cryptographic key data enciphered using 1 Doki 1 or a low rank leaf key, one or more cryptographic key data each stored in said validation keeping mouth Dug (E KB) The node of the right-and-left position of the low rank of a node position, or cryptographic key data of a leaf position It is a statement to Claim 29 generating as composition containing the tag in which existence is shown. Information processing method. 32. 前記有効化キ一ブロック (EKB) は、 前記キーツリ一を構成する各ノードに対応して設定されるノードキーを下位ノ 一ドキ一または下位リーフキーを用いて暗号化した暗号化キーデータと、 前記有効化キープ口ヅク(E KB)に格納された 1以上の暗号化キーデータ各々 のノード位置の下位の左右位置のノードまたはリーフ位置の暗号化キーデータの 有無を示すタグを含む構成として生成することを特徴とする請求項 29に記載の 情報処理方法。
  31. 33
    The above-mentioned validation key block (EKB) the end node or leaf which can decode the validation key block (EKB) -- the lowest Choose the path which constitutes the simplified tree which was used as the stage, and omit an unnecessary node. By It is dark about the key corresponding to the node or leaf of reconstruction hierarchy Tree reconstructed. To Claim 29 generating as composition which it has as item-ized key data Information processing method of a statement. 33. 前記有効化キーブロック (EKB) は、 該有効化キーブロック (EKB) を復号可能な末端ノードまたはリーフを最下 段とした簡略化したツリーを構成するパスを選択して不要ノードを省略すること により再構築される再構築階層ヅリーのノードまたはリーフに対応するキーを暗 号化キーデータとして有する構成として生成することを特徴とする請求項 29に 記載の情報処理方法。
  32. 34
    It is Keatuli 1 about a plurality of cryptographic key data contained in each of said composition E KB and a plurality of substitutes E K B. Claim 2 re-arranging and generating according to the node which can be set, or a leaf position Information processing method given in 9. 34. 前記合成 E KBは、 複数のサブ E K Bの各々に含まれる複数の暗号化キーデータを、 キーツリ一に おけるノードまたはリーフ位置に応じて再配列して生成することを特徴とする請 求項 2 9に記載の情報処理方法。
  33. 35
    3 5 . From Route of Tree Which Constituted a Plurality of Devices as a Leaf to Leaf Up Route on Path, A node and key tree which matched 1 with the leaf respectively It constitutes, The path which constitutes the 1 Tree is chosen, and it is based on the low rank key on a selection path. It has encryption processed data of a higher rank key, Node Keyset corresponding to the above-mentioned selection path Set to the device which can use A. 1 block (E K B) of validation which accepted and whose decoding it enabled It is validation keeping lock (E K B) generation processing in a system with the composition with which a device is provided Computer - Computer and program made to run on a system It is the recorded program recording medium, It decodes in each of Subtitled 1 set up as partial Rie of above-mentioned computer and program, and above-mentioned Key ring 1. 1 block of sub validation which can be processed (substitute E K B) Compositing process step, It is fixed-length data Feel about each of a plurality of key and data contained in composition E K B. Program recording medium having Step stored in Do. 3 5 . 複数のデバイスをリーフとして構成したヅリーのルートからリーフま でのパス上のルート、 ノード、 およびリーフに各々キ一を対応付けたキーツリー を構成し、 該キ一ヅリーを構成するパスを選択して選択パス上の下位キーによる 上位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ ト を利用可能なデバイスにおいてのみ復号可能とした有効化キ一ブロック( E K B ) をデバイスに提供する構成を持つシステムにおける有効化キープロック( E K B ) 生成処理をコンピュータ · システム上で実行せしめるコンピュータ · プログラム を記録したプログラム記録媒体であって、 前記コンピュータ · プログラムは、 前記キーヅリ一の部分ッリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キ一ブロック (サブ E K B ) の合成処理ステップと、 合成 E K B内に含まれる複数のキー ·データの各々を固定長のデータフィール ド内に格納するステヅプと、 を有することを特徴とするプログラム記録媒体。
  34. 36
    3 6 . From Route of Tree Which Constituted a Plurality of Devices as a Leaf to Leaf Route on Path, A node and 1 tree which matched the key with the leaf respectively It constitutes, the path which constitutes the key tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A It is an information processing system with the composition which provides Depice with 1 block of validation (E K B) whose decoding was enabled only in the device which can be used, The above-mentioned validation key block (E K B) It decodes in each of Subtitled 1 set up as partial Rie of above-mentioned Keatuli 1. It is constituted as composition E K B of sub validation keeping D Dug (substitute E K B) which can be processed, Key in the each sub validation Gyi 1-block (substitute E K B) which and it stores Arrangement is held, [ composition ] and -- corresponding to each substitute E K B -- the data length of a sub E K B storing field -- Information processing Si having the composition which called and added one sub E K B discernment De evening Stem. 3 6 . 複数のデバイスをリーフとして構成したヅリーのルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキ一ツリーを 構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キ一ブロック ( E K B ) をデパイスに提供する構成を持つ情報処理システムであり、 前記有効化キーブロック (E K B ) は、 前記キーツリ一の部分ッリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キープ Dヅク (サブ E K B )の合成 E K Bとして構成され、 該合成 E K Bは、 格納する各サブ有効化ギ一ブロック (サブ E K B ) 内のキー 配列を保持し、 かつ、 各サブ E K Bに対応してサブ E K B格納領域のデータ長お よびサブ E K B識別デ一夕を付加した構成を有することを特徴とする情報処理シ ステム。
  35. 37
    Above-mentioned Subtitled 1, It is classified based on a category, Category - Enti It is a category tree managed with a tee. 1 block of the above-mentioned sub validation (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to Category Lolli which is set and self manages. , -- it can process based on a Was done key Are generated as E K B. Key issue center 1. (KD C) It sets, The above-mentioned category - entity generates. It was substitute It is based on E KB, It is usable common to a plurality of Category 1. It is referred to as E KB. Composition of The Claim being adapted to generate E KB Information given in 3 6 Processing system. 37. 前記サブヅリ一は、 カテゴリに基づいて区分され、 カテゴリ ·ェンティ ティによって管理されるカテゴリツリーであり、 前記サブ有効化キ一ブロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリッリーに属するノードまたはリーフに対応付け られたキーに基づいて処理可能な E K Bとして生成され、 キー発行センタ一 (KD C) において、 前記カテゴリ · エンティティの生成し たサブ E KBに基づいて、 複数のカテゴリヅリ一に共通に使用可能な E KBとし ての合成 E KBを生成する構成であることを特徴とする請求項 3 6に記載の情報 処理システム。
  36. 38
    said 1 block of sub validation (substitute EKB) Al original with each and each Sub validation key block with Gorism and original key' data length (substitute EKB) As -- information processing system given in Claim 36 constituting. 38. 前記サブ有効化キ一ブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキー 'データ長を持つサブ有効化キーブロック (サブ EKB) として構成されていることを特徴とする請求項 36に記載の情報処理システム。
  37. 39
    3 9. Above-mentioned Subtitled 1, It is classified based on a category, Category ' Enti It is Category Lolli 1 managed with a tee. 1 block of the above-mentioned sub validation (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to Category Lolli which is set and self manages. , -- it can process based on a Was done key Are generated as E K B. Said composition. Each substitute in EKB Said substitute stored corresponding to E KB E KB discernment De One evening, Node which is an identifier of a node which constitutes category Tree It is I D. Claim by which it is characterized Information processing system given in 36. 3 9. 前記サブヅリ一は、 カテゴリに基づいて区分され、 カテゴリ ' ェンティ ティによって管理されるカテゴリッリ一であり、 前記サブ有効化キ一ブロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリッリーに属するノードまたはリーフに対応付け られたキーに基づいて処理可能な E K Bとして生成され、 前記合成 E KB内の各サブ E KBに対応して格納される前記サブ E KB識別デ 一夕は、 カテゴリヅリーを構成するノードの識別子であるノード I Dであること を特徴とする請求項 36に記載の情報処理システム。
  38. 40
    Each of sub validation key block (substitute EKB) stored in the above-mentioned composition E KB, It is a low rank node about the node key set up corresponding to each node which constitutes a key tree. Encryption 1 data enciphered using the key or the low rank leaf key, the node of the right-and-left position of the low rank of the node position of each cryptographic key data of said, or Li 1 It is the composition containing evening A which shows the existence of the cryptographic key data of a Off position. Claim 3 Information processing system given in 6. 40. 前記合成 E KBに格納されるサブ有効化キーブロック (サブ EKB) の 各々は、 キーツリーを構成する各ノードに対応して設定されるノードキーを下位ノード キーまたは下位リーフキーを用いて暗号化した暗号化キ一データと、 前記暗号化キーデータ各々のノード位置の下位の左右位置のノードまたはリ一 フ位置の暗号化キーデータの有無を示す夕グを含む構成であることを特徴とする 請求項 3 6に記載の情報処理システム。
  39. 41
    Each of sub validation key block (substitute EKB) stored in the above-mentioned composition E KB, the end node or leaf which can decode the substitute EK B was used as the lowest stage -- it simplified Choose the path which constitutes Tree and omit an unnecessary node. It is reconstructed. Let the key corresponding to the node or leaf of reconstruction hierarchy A dragon 1 be cryptographic key data. Information processing system given in Claim 36 carrying out Have. 41. 前記合成 E KBに格納されるサブ有効化キーブロック (サブ EKB) の 各々は、 該サブ E K Bを復号可能な末端ノードまたはリーフを最下段とした簡略化した ヅリーを構成するパスを選択して不要ノードを省略することにより再構築される 再構築階層ヅリ一のノードまたはリーフに対応するキーを暗号化キーデータとし て有することを特徴とする請求項 3 6に記載の情報処理システム。
  40. 42
    To Category Lolli 1 as subTree classified based on the category Configuration is carried out, From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on the path of until, Keatuli which matched the each key with the node and the leaf -- constituting -- The path which constitutes the key tree is chosen and it is to the low rank key on a selection path. At least a To top has encryption processed data of a key, Node Keyset corresponding to the above-mentioned selection path It is the information recording medium which stored validation keeping mouth A (E K B) whose decoding was enabled only in the device which can use A, It decodes in each of Sabilli 1 set up as partial A tree 1 of above-mentioned Key ring 1. 1 block of sub validation which can be processed (substitute EKB) Composition E KB is stored, this Synthesis corresponding to each substitute E KB contained in Formation E KB -- the one De evening length of a sub E KB storing field -- Information storage intermediation having the composition which called and stored sub E KB identification data The body. 42. カテゴリに基づいて区分されたサブヅリーとしてのカテゴリッリ一によ り構成され、 複数のデバイスをリーフとして構成したヅリーのルートからリーフ までのパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーツリ —を構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによ る上位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを利用可能なデバイスにおいてのみ復号可能とした有効化キープ口ック (E K B) を格納した情報記録媒体であり、 前記キーヅリ一の部分ッリ一として設定されるサブッリ一の各々において復号 処理可能なサブ有効化キ一ブロック (サブ EKB) の合成 E KBを格納し、 該合 成 E KB内に含まれる各サブ E KBに対応してサブ E KB格納領域のデ一夕長お よびサブ E KB識別データを格納した構成を有することを特徴とする情報記録媒 体。
  41. 43
    said sub validation key block (substitute EKB) Al original with each and each Sub validation key block with Gorism and original key' data length (substitute EKB) As -- information recording medium given in Claim 42 constituting. 43. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキー 'データ長を持つサブ有効化キーブロック (サブ EKB) として構成されていることを特徴とする請求項 42に記載の情報記録媒体。
  42. 44
    From the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Route on a path, A node and key Tree which matched the key with the leaf respectively It constitutes, the path which constitutes the key Tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A It is an information processing method in a system with the composition which provides a device with validation key block (EKB) whose decoding was enabled only in the device which can be used, It decodes in each of Subtitled 1 set up as partial Tree of the above-mentioned validation key block (EKB) and above-mentioned 1 A dragon 1. It is constituted as composition E KB of sub validation keeping mouth Dug (substitute E KB) which can be processed, The 1 block of each sub validation which and it stores (substitute EKB) Inner key Arrangement is held, [ composition ] and -- corresponding to each substitute E KB -- the data length of a sub E KB storing field -- as composition E K B with the composition which called and added one sub E KB discernment De evening -- a device -- Offer Offering information processing method. 44. 複数のデバイスをリーフとして構成したヅリ一のルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーヅリーを 構成し、 該キーヅリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック (EKB) をデバイスに提供する構成を持つシステムにおける情報処理方法であり、 前記有効化キーブロック (EKB) は、 前記キ一ヅリ一の部分ヅリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キープ口ヅク (サブ E KB)の合成 E KBとして構成され、 該合成 E KBは、 格納する各サブ有効化キ一ブロック (サブ EKB) 内のキー 配列を保持し、 かつ、 各サブ E KBに対応してサブ E KB格納領域のデータ長お よびサブ E KB識別デ一夕を付加した構成を持つ合成 E K Bとしてデバイスに提 供することを特徴とする情報処理方法。
  43. 45
    Above-mentioned Subtitled 1, It is classified based on a category, Category - Enti It is category Tree managed with a tee. the above-mentioned sub validation key block (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to category Tree which is set and self manages. , -- it can process based on a Was done key Are generated as E KB. Key issue center. (KD C) It sets, Said category ' An entity generates. It was substitute Based on E KB, it is usable common to a plurality of Category Lolli 1. It is referred to as E KB. Composition of The Claim generating E KB Information processing method given in 44. 45. 前記サブヅリ一は、 カテゴリに基づいて区分され、 カテゴリ · ェンティ ティによって管理されるカテゴリヅリーであり、 前記サブ有効化キーブロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリヅリーに属するノードまたはリーフに対応付け られたキーに基づいて処理可能な E KBとして生成され、 キー発行センター (KD C) において、 前記カテゴリ ' エンティティの生成し たサブ E KBに基づいて、 複数のカテゴリッリ一に共通に使用可能な E KBとし ての合成 E KBを生成することを特徴とする請求項 44に記載の情報処理方法。
  44. 46
    said sub validation key block (substitute EKB) . Al original with each and each Sub validation key block with Gorism and original key' data length (substitute EKB) As -- information processing method given in Claim 44 constituting. 46. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自の.アル ゴリズム、 独自のキー 'データ長を持つサブ有効化キーブロック (サブ EKB) として構成されることを特徴とする請求項 44に記載の情報処理方法。
  45. 47
    The above-mentioned subtree, It is classified based on a category, Category ' Enti It is a category tree managed with a tee. the above-mentioned sub validation key block (sub E K B) Is the above-mentioned category. 'entity Match with A 1 Do or a leaf belonging to Category Lolli 1 which is set and self manages. , -- it can process based on Killed 1 Are generated as E K B. Each substitute in said composition E K B. Said substitute stored corresponding to E K B E K B discernment De One evening, Node which is an identifier of a node which constitutes Category 1 It is I D. Claim by which it is characterized Information processing method given in 4 4. 47. 前記サブツリーは、 カテゴリに基づいて区分され、 カテゴリ ' ェンティ ティによって管理されるカテゴリツリーであり、 前記サブ有効化キーブロック (サブ E K B ) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリッリ一に属するノ一ドまたはリーフに対応付け られたキ一に基づいて処理可能な E K Bとして生成され、 前記合成 E K B内の各サブ E K Bに対応して格納される前記サブ E K B識別デ 一夕は、 カテゴリヅリ一を構成するノードの識別子であるノード I Dであること を特徴とする請求項 4 4に記載の情報処理方法。
  46. 48
    4 8 . Sub Validation Key Block Stored in the Above-mentioned Composition E K B (Substitute E K B) Each, It is a low rank node about the node key set up corresponding to each node which constitutes Keatuli 1. Cryptographic key data enciphered using the key or the low rank leaf key, the node of the right-and-left position of the low rank of the node position of each cryptographic key data of said, or Li 1 Claim 4 containing evening A which shows the existence of the cryptographic key data of a Off position Information processing method given in 4. 4 8 . 前記合成 E K Bに格納されるサブ有効化キーブロック (サブ E K B ) の 各々は、 キーツリ一を構成する各ノードに対応して設定されるノードキーを下位ノード キーまたは下位リーフキーを用いて暗号化した暗号化キーデータと、 前記暗号化キーデータ各々のノード位置の下位の左右位置のノードまたはリ一 フ位置の暗号化キーデータの有無を示す夕グを含むことを特徴とする請求項 4 4 に記載の情報処理方法。
  47. 49
    4 9 . Sub Validation Key Block Stored in the Above-mentioned Composition E K B (Substitute E K B) Each, the end node or leaf which can decode the substitute E K B was used as the lowest stage -- it simplified Choose the path which constitutes A dragon 1 and omit an unnecessary node. It is reconstructed. Let the key corresponding to the node or leaf of reconstruction hierarchy Tree be cryptographic key data. Information processing method given in Claim 4 carrying out Have. 4 9 . 前記合成 E K Bに格納されるサブ有効化キーブロック (サブ E K B ) の 各々は、 該サブ E K Bを復号可能な末端ノードまたはリーフを最下段とした簡略化した ヅリ一を構成するパスを選択して不要ノードを省略することにより再構築される 再構築階層ヅリーのノードまたはリーフに対応するキーを暗号化キーデータとし て有することを特徴とする請求項 4 に記載の情報処理方法。
  48. 50
    5 0 . From Le 1 A of Tree Which Constituted a Plurality of Devices as a Leaf to Leaf Route on Path, A node and key Tree which matched 1 with the leaf respectively It constitutes, the path which constitutes the Key ring 1 is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A Set to the device which can be used. Validation key block which accepted and whose decoding it enabled (E K B) It is validation keeping lock (E K B) generation processing in a system with the composition with which a device is provided Computer - Computer and program made to run on a system It is the recorded program recording medium, It decodes in each of subTree set up as partial Tree of above-mentioned computer and program, and above-mentioned Keatuli 1. Sub validation key block which can be processed (substitute EKB) Selection step, The program recording medium having a step which adds the data length of a sub E KB storing field, and one sub E K B discernment De evening corresponding to each selection sub E KB. 5 0 . 複数のデバイスをリーフとして構成したヅリーのル一トからリーフまで のパス上のルート、 ノード、 およびリーフに各々キ一を対応付けたキーヅリーを 構成し、 該キーヅリ一を構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック ( E K B ) をデバイスに提供する構成を持つシステムにおける有効化キープロック( E K B ) 生成処理をコンピュータ · システム上で実行せしめるコンピュータ · プログラム を記録したプログラム記録媒体であって、 前記コンピュータ · プログラムは、 前記キーツリ一の部分ヅリーとして設定されるサブヅリーの各々において復号 処理可能なサブ有効化キーブロック (サブ EKB) の選択ステップと、 各選択サブ E KB.に対応してサブ E KB格納領域のデータ長およびサブ E K B 識別デ一夕を付加するステップと、 を有することを特徴とするプログラム記録媒体。
Independent claims48