Information processing system and method
Abstract
An information processing system and method for realizing efficient processing using an enabling key block (EKB) using a categorized tree structure. An EKB composed of encrypting data for encrypting an upper-order key by using a lower-order key on a selection path of a key tree having sub-trees managed by a category entity is created and provided to a device. When a request to create an EKB is made, a structure for creating a route key by itself or a structure for requesting a key distribution center to create a route key is selectively executed. Further a structure for requesting a category entity to create a sub-EKB when the EKB distribution center creates an EKB is provided, and therefore the EKB creation and management are made efficient.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
50 claims: 48 independent, 2 dependent
- 1The range 1 of a claim. From the route of Rie which constituted a plurality of devices as a leaf to a leaf Route on a path, It is a style about a node and the key tree which matched the key with the leaf respectively. It accomplishes, Higher rank choose the path which constitutes the 1 Tree, and according to low rank 1 on a selection path It has one encryption processing De evening of a key, Node tree 1 Set corresponding to the above-mentioned selection path It is a profit about A. It is an information processing system with the composition which provides a device with validation key block (EKB) whose decoding was enabled only in the device in which for is possible, As opposed to 1 issue center (KD C) which generates validation key block (EKB) EKB requester which requires generation of The EKB, The 1st E KB generation demand as a E KB generation demand containing a generated Le 1 smallness key, or the roux in key issue center (KD C) -- a crested ibis -- 1 generation and the generation route key E KB generation demand of The 2 which requires the E KB generation to include, as a E K B generation demand of as opposed to key issue center 1 (KD C) for whether it is Either -- output it carries out -- a key issue center (KD C) and E KB generation demand of above-mentioned The 1, responding to reception of or a E KB generation demand of above-mentioned The 2 -- a receiving roux -- crested ibis 1 or a generation roux -- the information Treatment system having the composition which performs E KB generation including crested ibis 1. 請求の範囲 1. 複数のデバイスをリーフとして構成したッリーのルートからリーフまでの パス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーツリーを構 成し、 該キ一ヅリーを構成するパスを選択して選択パス上の下位キ一による上位 キーの暗号化処理デ一夕を有し、 前記選択パスに対応するノードキ一セッ トを利 用可能なデバイスにおいてのみ復号可能とした有効化キーブロック (EKB) を デバイスに提供する構成を持つ情報処理システムであり、 有効化キーブロック (EKB) を生成するキ一発行センター (KD C) に対し て EKBの生成を要求する EKBリクエスタは、 生成済みル一小キーを含む E KB生成要求としての第 1の E KB生成要求、 ま たは、 キー発行センター (KD C) におけるルートキ一生成および該生成ルートキー を含む E KB生成を要求する第 2の E KB生成要求、 のいずれかをキー発行センタ一 (KD C) に対する E K B生成要求として出力 し、 キー発行センター (KD C) は、 前記第 1の E KB生成要求、 または前記第 2 の E KB生成要求の受信に応じて受信ルートキ一または生成ルートキ一を含めた E KB生成を実行する構成を有することを特徴とする情報処瑪システム。
- 3Said E KB requester, a memory measure, or Netsai on Network which can be perused The EKB evening acquired from A It is the feature about it being the composition which chooses a E KB type identifier based on a A definition list. Information processing system given in Claim 2 to carry out. 3. 前記 E KBリクエスタは、 記憶手段、 または、 ネッ トワーク上の閲覧可能サイ トから取得される EKB夕 ィプ定義リストに基づいて E KBタイプ識別子を選択する構成であることを特徴 とする請求項 2に記載の情報処理システム。
- 4Discernment De of category Tree which said E KB type definition list can E KB process It is the feature about their being one evening and node I D which is the identifiers of the node of Category 1. Information processing system given in Claim 2 to carry out. 4. 前記 E KBタイプ定義リストの E KB処理可能なカテゴリヅリーの識別デ 一夕は、 カテゴリヅリ一のノードの識別子であるノード I Dであることを特徴と する請求項 2に記載の情報処理システム。
- 5It is Seki to the device which belongs to said EKB type definition list at a category tree. Information processing system given in Claim 2 being composition including the explanation to give 5. 前記 EKBタイプ定義リストには、 カテゴリツリーに属するデバイスに関 する説明を含む構成であることを特徴とする請求項 2に記載の情報処理システム
- 6From the route of Tree which constituted a plurality of Depice as a leaf to a leaf Route on a path, Node, It is a style about 1 Tree which reached and matched a key with a leaf respectively. It accomplishes, A path which constitutes the Key ring 1 is chosen and it is on a selection path. Higher rank by C low rank 1 ' It has encryption processed data of a key, Node Keyset corresponding to the above-mentioned selection path It is a profit about A. Validation key pro who made decoding possible only in Depice in which for is possible Dug (EKB) It is an information processing system with composition with which a device is provided, Above-mentioned Key ring 1, It is classified based on a category, Category To 'entity It is the composition which carries out two or more owners of the category Tree as Sub tree therefore managed. 1 block of validation (EKB) Key issue center to generate (KD C) Is E It is a demand entity of KB generation. Validation based on a demand of the E KB Request evening Keeping lock (EKB) In generation, Validation key block to generate. (EKB) Category Tree which can be decoded is managed. One or more categories It is each power to - Endy. In a Age tree, he is a substitute who can process. A generation demand of E KB is outputted, Category. Sub validation key block received from * Entity (substitute EKB) It is based. It can process in one or more Category 1. It is Special about having the composition which generates E KB. Information processing system considered as a mark. 6. 複数のデパイスをリーフとして構成したヅリーのルートからリーフまでの パス上のルート、 ノード、 およびリーフに各々キーを対応付けたキ一ヅリーを構 成し、 該キーヅリ一を構成するパスを選択して選択パス上 C 下位キ一による上位 ' キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを利 用可能なデパイスにおいてのみ復号可能とした有効化キープロ ヅク (EKB) を デバイスに提供する構成を持つ情報処理システムであり、 前記キーヅリ一は、 カテゴリに基づいて区分され、 カテゴリ 'エンティティに よって管理されるサブッリーとしてのカテゴリヅリーを複数有する構成であり、 有効化キ一ブロック (EKB) を生成するキー発行センター (KD C) は、 E KB生成の要求エンティティである E KBリクエス夕の要求に基づく有効化 キープロック (EKB) の生成において、 生成する有効化キーブロック (EKB) の復号可能なカテゴリヅリーを管理する 1以上のカテゴリ ·エンディティに各力 テゴリツリーにおいて処理可能なサブ E KBの生成要求を出力し、 カテゴリ * ェ ンティティから受領したサブ有効化キーブロック (サブ EKB) に基づいて 1以 上のカテゴリヅリ一において処理可能な E KBを生成する構成を有することを特 徴とする情報処理システム。
- 8Kate who received the sub EKB generation demand from the above-mentioned key issue center (KD C) Gori and entity, It is based on the key matched with The node belonging to the category tree of self to manage, or Li - Off, and is a sub validation key block as E KB which can be processed. (substitute EKB) It indicates to Claim 6 being the composition to generate. Information processing system. 8. 前記キー発行センター (KD C) からサブ EKB生成要求を受領したカテ ゴリ ·エンティティは、 自己の管理するカテゴリツリーに属するノードまたはリ ーフに対応付けられたキーに基づいて処理可能な E KBとしてのサブ有効化キー ブロック (サブ EKB) を生成する構成であることを特徴とする請求項 6に記載 の情報処理システム。
- 9two or more steps of route Tree are constituted by the above-mentioned 1 Tree and the highest rung -- the route It links with A dragon 1 directly. Tap level and category Tree, the Tap level Category it is constituted by subcategory Tree connected with Li's 1 lower berth -- the above-mentioned category and Entity, Pipe science and engineering of above-mentioned top-level and Category It carries out and he is the Tap level Category Lolli 1 and the top-level . Kate. Subcategory Tree which stands in a row in the lower berth of Gori lily is managed, The above-mentioned category' Li entity, Self manages. Top-level and Category Lolli 1 and the A To subCategory Lolli which stands in a row in the lower berth of Level and Category Lolli 1 It corresponds to the node or leaf which belongs. It is based on the key set up and is a sub validation key block as E K B which can be processed. (substitute EKB) It is the composition to generate. Information processing system given in Claim 6 by which it is characterized. 9. 前記キ一ヅリーは、 最上段に複数段のルートヅリーが構成され、 該ルート ヅリ一に直結する ト ヅプレベル · カテゴリヅリー、 該トヅプレベル · カテゴリヅ リ一の下段に連結されるサブカテゴリヅリーによって構成され、 前記カテゴリ · ェンティティは、 前記トップレベル · カテゴリッリーの管理工 ンティティ として該トヅプレベル · カテゴリッリ一および該トップレベル . カテ ゴリヅリーの下段に連なるサブカテゴリヅリーの管理を行ない、 前記カテゴ 'リ ·エンティティは、 自己の管理する トップレベル · カテゴリッリ 一および該ト ヅプレベル · カテゴリッリ一の下段に連なるサブカテゴリッリーに 属するノードまたはリーフに対応して設定されるキーに基づいて処理可能な E K Bとしてのサブ有効化キーブロック (サブ EKB) を生成する構成であることを 特徴とする請求項 6に記載の情報処理システム。
- 101 0. From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on a path, It is a pair about a key respectively to a node and a leaf. Attached Key ring 1 It constitutes, the path which constitutes the 1 Tree is chosen, and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Kisera corresponding to the above-mentioned selection path A 1 block of validation whose decoding was enabled only in the device which can be used (epsilonkappabeta) It is an information processing method in a system with the composition with which a device is provided, Validation key block (epsilonkappabeta) As opposed to key issue center 1 (KD C) to generate E KB requester which requires generation of The E KB, The E KB generation demand of The 1 as a E KB generation demand containing a generated route key, Or the route key generation in key issue center 1 (KD C) and the generation route key E KB generation demand of The 2 which requires the E KB generation to include, as a E KB generation demand of as opposed to key issue center (KD C) for whether it is Either -- output it carries out -- key issue center (KD C) and EKB generation demand of above-mentioned The 1, An information processing method performing E KB generation which includes a receiving route key or a generation route key according to reception of or a E KB generation demand of above-mentioned The 2. 1 0. 複数のデバイスをリーフとして構成したヅリーのルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対 付けたキーヅリ一を 構成し、 該キ一ヅリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセヅ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キ一ブロック (ΕΚΒ) をデバイスに提供する構成を持つシステムにおける情報処理方法であり、 有効化キーブロック (ΕΚΒ) を生成するキー発行センタ一 (KD C) に対し て E KBの生成を要求する E KBリクエスタは、 生成済みルートキーを含む E KB生成要求としての第 1の E KB生成要求、 ま たは、 キー発行センタ一 (KD C) におけるルートキー生成および該生成ルートキー を含む E KB生成を要求する第 2の E KB生成要求、 のいずれかをキー発行センター (KD C) に対する E KB生成要求として出力 し、 キー発行センター (KD C) は、 前記第 1の EKB生成要求、 または前記第 2 の E KB生成要求の受信に応じて受信ルートキーまたは生成ルートキーを含めた E KB生成を実行することを特徴とする情報処理方法。
- 111 1. it is Classified Based on the Above-mentioned 1 Tree and Category -- Category Enti Composition Which Carries Out Two or More Owners of Category 1 as SubTree Managed with Tee There, The above-mentioned EKB requester chooses a E KB type identifier based on the E KB type definition list which matched the E KB type identifier and one discernment De evening of category Tree in which E KB processing is possible, It is [ the E KB generation demand of said The 1, or ] a front about the E KB generation demand containing a selection E KB type identifier. It is Output to said key issue center (KD C) as an EKB generation demand of account The 2. Claim 1 characterized by To Information processing method given in 0. 1 1. 前記キ一ヅリーは、 カテゴリに基づいて区分され、 カテゴリ · ェンティ ティによって管理されるサブヅリーとしてのカテゴリヅリ一を複数有する構成で あり、 前記 EKBリクエスタは、 E KBタイプ識別子と、 E KB処理可能なカテゴリヅリーの識別デ一夕とを対 応付けた E KBタイプ定義リストに基づいて E KBタイプ識別子を選択し、 選択 E KBタイプ識別子を含む E KB生成要求を前記第 1の E KB生成要求または前 記第 2の EKB生成要求として前記キー発行センター (KD C) に対して出力す ることを特徴とする請求項 1 0に記載の情報処理方法。
- 12The above-mentioned E KB requester, a memory measure, or Netsai on Network which can be perused The EKB evening acquired from A Claim choosing a E KB type identifier based on a A definition list Paragraph 1 Information processing method given in 1. 12. 前記 E KBリクエスタは、 記憶手段、 または、 ネッ トワーク上の閲覧可能サイ トから取得される EKB夕 ィプ定義リストに基づいて E KBタイプ識別子を選択することを特徴とする請求 項 1 1に記載の情報処理方法。
- 131 3. Discernment of category Tree which said E KB type definition list can E KB process It is the feature about their being data and node I D which is the identifiers of the node of category Tree. Claim 1 to carry out Information processing method given in 1. 1 3. 前記 E KBタイプ定義リストの E KB処理可能なカテゴリヅリーの識別 データは、 カテゴリヅリーのノードの識別子であるノード I Dであることを特徴 とする請求項 1 1に記載の情報処理方法。
- 14To the device which belongs to said E KB type definition list at a category tree Claim 1 being composition including the related explanation Information processing method given in 1. 14. 前記 E KBタイプ定義リストには、 カテゴリツリーに属するデバイスに 関する説明を含む構成であることを特徴とする請求項 1 1に記載の情報処理方法。
- 151 5. From Le 1 A of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Route on a path, - Do, And key tree which matched a key with a leaf respectively It constitutes, a path which constitutes the key Tree is chosen and it is based on a low rank key on a selection path -- the upper -- , about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A Validation 1 Plock whose decoding was enabled only in a device which can be used (EKB) It is an information processing method in a system with composition with which a device is provided, The above-mentioned key tree, It is classified based on a category, Category ' To an entity It is the composition which carries out two or more owners of the category Tree as subTree therefore managed. validation key block (EKB) Key issue center to generate (KD C) Is E It is a demand entity of KB generation. Validation based on a demand of a E KB requester Key block (EKB) In generation, Validation key block to generate. (EKB) Category 1 which can be decoded is managed. One or more categories It is each power to - entity. In a Age tree, he is a substitute who can process. A generation demand of EKB is outputted, Category. Sub validation key block received from 'Entity (sub EKB) It is based. It can process in one or more Category 1. Information generating E KB Disposal method. 1 5. 複数のデバイスをリーフとして構成したヅリ一のル一トからリーフまで のパス上のルート、 ード、 およびリーフに各々キーを対応付けたキーツリーを 構成し、 該キーヅリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キ一プロック (EKB) をデバイスに提供する構成を持つシステムにおける情報処理方法であり、 前記キーツリーは、 カテゴリに基づいて区分され、 カテゴリ ' エンティティに よって管理されるサブヅリーとしてのカテゴリヅリーを複数有する構成であり、 有効化キーブロック (EKB) を生成するキー発行センター (KD C) は、 E KB生成の要求エンティティである E KBリクエスタの要求に基づく有効化 キーブロック (EKB) の生成において、 生成する有効化キーブロック (EKB) の復号可能なカテゴリヅリ一を管理する 1以上のカテゴリ · エンティティに各力 テゴリツリーにおいて処理可能なサブ E KBの生成要求を出力し、 カテゴリ ' ェ ンティティから受領したサブ有効化キーブロック (サブ EKB) に基づいて 1以 上のカテゴリヅリ一において処理可能な E KBを生成することを特徴とする情報 処理方法。
- 161 6. Above-mentioned Key Issue Center (KD C) E It is a pair about KB type identifier and the identification data of Category Lolli in which E KB processing is possible. It has a beam E KB type definition list with Response, E entity which requires generation of KB it is -- E KB type included during the E KB generation demand received from a E KB requester the search of a E K B type definition list based on an identifier -- discernment day of Category 1 Extract the evening. One or more Kate corresponding to the identification data of extracted category Lily Gori . It is based on substitute E KB whom the entity generated, E KB type definition squirrel Composition which generates and provides with E KB usable in common Category 1 set as A it is -- Claim 1 characterized by things Information processing method given in 5. 1 6. 前記キー発行センター (KD C) は、 E KBタイプ識別子と、 E KB処理可能なカテゴリッリーの識別データとを対 応付けた E KBタイプ定義リストを有し、 E KBの生成を要求するエンティティ である E KBリクエスタから受領する E KB生成要求中に含まれる E KBタイプ 識別子に基づく E K Bタイプ定義リストの検索によりカテゴリヅリ一の識別デー 夕を抽出して、 抽出されたカテゴリヅリーの識別データに対応する 1以上のカテ ゴリ . エンティティの生成したサブ E KBに基づいて、 E KBタイプ定義リス ト に設定されたカテゴリヅリ一に共通に使用可能な E KBを生成して提供する構成 であることを特徴とする請求項 1 5に記載の情報処理方法。
- 171 7. Power Which Received Sub E KB Generation Demand from Above-mentioned Key Issue Center (KD C) Age and Entity, the node belonging to category Tree of self to manage -- or -- being based on the key matched with the leaf -- sub validation as EKB which can be processed 1 block (substitute EKB) Generating Claim 1 Information given in 5 Disposal method. 1 7. 前記キー発行センター (KD C) からサブ E KB生成要求を受領した力 テゴリ ·エンティティは、 自己の管理するカテゴリヅリーに属するノードまたは リーフに対応付けられたキーに基づいて処理可能な EKBとしてのサブ有効化キ 一ブロック (サブ EKB) を生成することを特徴とする請求項 1 5に記載の情報 処理方法。
- 181 8. Two or More Steps of Route Trees are Constituted by Above-mentioned Key ring 1 and Highest Rung, The roux It links with Tori 1 directly. A Tap level' category tree and the Tap level - Category It is constituted by subcategory Tree connected with the lower berth of Rie, Pipe science and engineering of the above-mentioned category 'entity and above-mentioned top level' category Tree They are Category 1 and top-level 'top level' Kate as Entity. SubCategory 1 which stands in a row in the lower berth of Gorelli 1 is managed, The above-mentioned category and entity, self--- Tap level Category which 3 manages Subcategory Tree which stands in a row in the lower berth of 1, and the Tap level and Category Lolli Correspond to the node or leaf which belongs. It is based on the key set up and is a sub validation key block as E K B which can be processed. (substitute EKB) It generates. Claim 1 Information processing method given in 5. 1 8. 前記キーヅリ一は、 最上段に複数段のルートツリーが構成され、 該ルー トヅリ一に直結する ト ヅプレベル ' カテゴリツリー、 該トヅプレベル · カテゴリ ッリーの下段に連結されるサブカテゴリヅリーによって構成され、 前記カテゴリ ' エンティティは、 前記トップレベル ' カテゴリヅリーの管理工 ンティティとして該トップレベル ' カテゴリヅリ一および該トップレベル ' カテ ゴリッリ一の下段に連なるサブカテゴリヅリ一の管理を行ない、 前記カテゴリ ·エンティティは、 自 3の管理するトヅプレベル · カテゴリヅリ 一および該トヅプレベル · カテゴリッリーの下段に連なるサブカテゴリヅリーに 属するノードまたはリーフに対応して設定されるキーに基づいて処理可能な E K Bとしてのサブ有効化キーブロック (サブ EKB) を生成することを特徴とする 請求項 1 5に記載の情報処理方法。
- 191 9. From the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Route on a path, A node and key tree which matched the key with the leaf respectively It constitutes, the path which constitutes the key tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A Set to the device which can be used. Computer - which makes the information processing in a system with the composition which provides Depice with validation key block (E K B) which accepted, and whose decoding it enabled perform on computer and a system Program record intermediation which recorded the program It is the body, Above-mentioned computer and program, and the E K B generation demand of The 1 as a E K B generation demand containing a generated route key, Or the route key generation in key issue center (K D C) and the generation route One E K B generation of the E K B generation demands of The 2 which requires the E K B generation containing a key Step which receives a demand, E K B generation which includes a receiving route key according to the kind of received E K B generation demand, or a roux -- either of the E K B generation including generation of crested ibis 1, and a generation route key Program recording medium having a step which performs processing alternatively. 1 9. 複数のデバイスをリーフとして構成したヅリ一のルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーツリーを 構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック ( E K B ) をデパイスに提供する構成を持つシステムにおける情報処理をコンピュータ · シ ステム上で実行せしめるコンピュータ · プログラムを記録したプログラム記録媒 体であって、 前記コンピュータ · プログラムは、 生成済みルートキーを含む E K B生成要求としての第 1の E K B生成要求、 ま たは、 キー発行センター (K D C ) におけるルートキー生成および該生成ルート キーを含む E K B生成を要求する第 2の E K B生成要求のいずれかの E K B生成 要求を受信するステップと、 受信した E K B生成要求の種類に応じて、受信ルートキーを含めた E K B生成、 またはルートキ一の生成および生成ルートキーを含めた E K B生成のいずれかの 処理を選択的に実行するステップと、 を有することを特徴とするプログラム記録媒体。
- 202 0 . From the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Route on a path, A node and key tree which matched 1 with the leaf respectively It constitutes, the path which constitutes the key Tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A Set to the device which can be used. Computer - which makes the information processing in a system with the composition which provides a device with validation key block (E K B) which accepted, and whose decoding it enabled perform on computer and a system Program record intermediation which recorded the program It is the body, Above-mentioned computer and program are based on the E K B type identifier contained in a E K B generation demand, and is E K B type discernment. Child, E The step which extracts one discernment De evening of Category Lolli from the E K B type definition list which matched the identification data of one or more category trees in which K B processing is possible, setting at each category Tree to one or more category entities which manage category Tree corresponding to the identification data of Category 1 of which extraction was done -- the substitute who can process -- an owner -- The step which outputs the generation demand of effect-ized key block (substitute E K B), and category, Sub validation key block received from 'entity (substitute EKB) Steps which is based and generates E KB which can be processed in one or more category Tree Program recording medium having A. 2 0 . 複数のデバイスをリーフとして構成したヅリ一のルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キ一を対応付けたキーツリーを 構成し、 該キーヅリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック (E K B ) をデバイスに提供する構成を持つシステムにおける情報処理をコンピュータ · シ ステム上で実行せしめるコンピュータ · プログラムを記録したプログラム記録媒 体であって、 前記コンピュータ · プログラムは、 E K B生成要求に含まれる E K Bタイプ識別子に基づいて、 E K Bタイプ識別 子と、 E K B処理可能な 1以上のカテゴリツリーの識別データとを対応付けた E K Bタイプ定義リストからカテゴリッリーの識別デ一夕を抽出するステップと、 抽出されたカテゴリヅリ一の識別データに対応するカテゴリヅリーを管理する 1以上のカテゴリ · エンティティに各カテゴリヅリーにおいて処理可能なサブ有 効化キーブロック (サブ E K B ) の生成要求を出力するステップと、 カテゴリ、, ' エンティティから受領したサブ有効化キーブロック (サブ EKB) に基づいて 1以上のカテゴリヅリーにおいて処理可能な E KBを生成するステヅ プと、 を有することを特徴とするプログラム記録媒体。
- 212 1. From Route of A tree 1 Which Constituted a Plurality of Devices as Leaf to Leaf Route on Path, Key ring 1 which matched the key with the node and the leaf respectively It constitutes, the path which constitutes the Keatuli 1 is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Kisera corresponding to the above-mentioned selection path A It is an information processing system with the composition which provides Depice with validation key block (EKB) whose decoding was enabled only in the device which can be used, It decodes in each of Subtitled 1 set up as partial Tree of the above-mentioned validation key block (EKB) and above-mentioned Keatuli 1. It is constituted as composition E KB of sub validation keeping mouth A (substitute E KB) which can be processed, De 1 taffy 1 Le of fixed length [ each / of a plurality of key and one De evenings contained in the composition E KB ] Information processing system having the composition stored in Do. 2 1. 複数のデバイスをリーフとして構成したッリ一のルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーヅリ一を 構成し、 該キーツリ一を構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセヅ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック (EKB) をデパイスに提供する構成を持つ情報処理システムであり、 前記有効化キーブロック (EKB) は、 前記キーツリ一の部分ヅリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キープ口ック (サブ E KB)の合成 E KBとして構成され、 該合成 E KB内に含まれる複数のキー ·デ一夕の各々が固定長のデ一タフィ一ル ド内に格納された構成を有することを特徴とする情報処理システム。
- 22The above-mentioned subtree, It is classified based on a category, Category 'Enti It is Category Lolli 1 managed with a tee. the above-mentioned sub validation key block (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to category Tree which is set and self manages. , -- it can process based on a Was done key It is generated as E K B. In key issue center 1 (KD C) Said category. 'entity generates. It was substitute Based on E K B, it is usable common to a plurality of category Tree. It is referred to as E K B. Composition of The Claim being adapted to generate E KB Information given in 2 1 Processing system. 22. 前記サブツリーは、 カテゴリに基づいて区分され、 カテゴリ 'ェンティ ティによつて管理されるカテゴリッリ一であり、 前記サブ有効化キーブロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリヅリーに属するノードまたはリーフに対応付け られたキーに基づいて処理可能な E K Bとして生成され、 キー発行センタ一 (KD C) において、 前記カテゴリ ' エンティティの生成し たサブ E K Bに基づいて、 複数のカテゴリヅリーに共通に使用可能な E K Bとし ての合成 E KBを生成する構成であることを特徴とする請求項 2 1に記載の情報 処理システム。
- 23The above-mentioned sub validation key block (substitute EKB) Each, respectively -- original Al Sub validation key block with Gorism and original key' data length (substitute EKB) As -- it is constituted -- key issue Seng evening 1 (K D C) In the generation processing of composition E K B based on the above-mentioned substitute E K B, It is Construct about composition E K B. Each of the key . data in To substitute E K B is stored in a fixed-length data field. Claim 2 being the composition of performing processing Information processing system given in 1. 23. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキー 'データ長を持つサブ有効化キーブロック (サブ EKB) として構成され、 キー発行セン夕一 (K D C ) は、 前記サブ E K Bに基づく合成 E K Bの生成処理において、 合成 E K Bを構成す るサブ E K B内のキー .データの各々を固定長のデータフィールド内に格納する 処理を実行する構成であることを特徴とする請求項 2 1に記載の情報処理システ ム。
- 242 4 . It is Low Rank A about Node Key Set Up corresponding to Each Node Which Constitutes the Above-mentioned Composition E K B and Above-mentioned Key ring 1. Cryptographic Key Data Enciphered Using 1 Do key or Low Rank Leaf Key, one or more node positions of each one encryption Kee de evening stored in said composition E K B -- lower -- Tag in which the existence of the node of the right-and-left position of an about or the cryptographic key data of a leaf position is shown Claim 2 being the composition to include Information processing system given in 1. 2 4 . 前記合成 E K Bは、 前記キーヅリ一を構成する各ノードに対応して設定されるノードキーを下位ノ 一ドキーまたは下位リーフキーを用いて暗号化した暗号化キーデータと、 前記合成 E K Bに格納された 1以上の暗号化キーデ一夕各々のノード位置の下 位の左右位置のノードまたはリーフ位置の暗号化キーデータの有無を示すタグを 含む構成であることを特徴とする請求項 2 1に記載の情報処理システム。
- 252 5 . The Above-mentioned Composition E K B the end node or leaf which can decode the composition E K B was used as the lowest stage -- it simplified Choose the path which constitutes Tree and omit an unnecessary node. It is reconstructed. Let the key corresponding to the node or leaf of reconstruction hierarchy Tree be one encryption Kee de evening. Claim 2 carrying out Have Information processing system given in 1. 2 5 . 前記合成 E K Bは、 該合成 E K Bを復号可能な末端ノードまたはリーフを最下段とした簡略化した ヅリーを構成するパスを選択して不要ノードを省略することにより再構築される 再構築階層ヅリーのノードまたはリーフに対応するキーを暗号化キーデ一夕とし て有することを特徴とする請求項 2 1に記載の情報処理システム。
- 262 6 . It is key Tree about a plurality of cryptographic key data contained in each of said composition E K B and a plurality of substitutes E K B. It has the composition which re-arranged and was generated according to the node which can be set, or the leaf position. Claim 2 by which it is characterized Information processing system given in 1. 2 6 . 前記合成 E K Bは、 複数のサブ E K Bの各々に含まれる複数の暗号化キーデータを、 キーヅリーに おけるノードまたはリーフ位置に応じて再配列して生成された構成を有すること を特徴とする請求項 2 1に記載の情報処理システム。
- 272 7 . To Category Tree as SubTree Classified Based on Category Configuration is Carried Out, From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on the path of until, A node and 1 A dragon which matched the key with the leaf respectively 1 is constituted, The path which constitutes the key tree is chosen and it is to the low rank key on a selection path. At least a To top has encryption processed data of a key, Node Kisera corresponding to the above-mentioned selection path It is the information recording medium which stored validation 1 Plock (E K B) whose decoding was enabled only in the device which can use A, It decodes in each of Sabilli 1 set up as partial Tree of above-mentioned Keatuli 1. Sub validation key block which can be processed (substitute EKB) Composition E KB is stored, This Synthesis Inside of the one De evening field of fixed length [ each / of a plurality of key data contained in Formation E KB ] Information recording medium having the stored composition. 2 7 . カテゴリに基づいて区分されたサブヅリーとしてのカテゴリツリーによ り構成され、 複数のデバイスをリーフとして構成したヅリーのルートからリーフ までのパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキ一ヅリ 一を構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによ る上位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセヅ トを利用可能なデバイスにおいてのみ復号可能とした有効化キ一プロック (E K B) を格納した情報記録媒体であり、 前記キーツリ一の部分ヅリーとして設定されるサブッリ一の各々において復号 処理可能なサブ有効化キーブロック (サブ EKB) の合成 E KBを格納し、 該合 成 E KB内に含まれる複数のキー ·データの各々が固定長のデ一夕フィールド内 に格納された構成を有することを特徴とする情報記録媒体。
- 28The above-mentioned sub validation key block (substitute EKB) Each, respectively -- original Al Gorism and 1 block of sub validation with original 1' data length (substitute EKB) As -- it is constituted -- the storing field of key and data is the composition made into fixed length Information recording medium given in Claim 27 by which it is characterized. 28. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキ一 'データ長を持つサブ有効化キ一ブロック (サブ EKB) として構成され、 キー ·データの格納領域が固定長とされている構成であること を特徴とする請求項 27に記載の情報記録媒体。
- 29From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on a path, Key ring 1 which matched the key with the node and the leaf respectively It constitutes, the path which constitutes the key tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node key set corresponding to the above-mentioned selection path It is an information processing method in a system with the composition which provides a device with validation keeping mouth A (EKB) whose decoding was enabled only in the device which can be used, It decodes in each of Subtitled 1 set up as partial Tree of the above-mentioned validation key block (EKB) and above-mentioned Key ring 1. It is constituted as composition EKB of sub validation 1 Prozek (substitute E KB) which can be processed, Day taffy 1 Le of fixed length [ each / of a plurality of key and one De evenings contained in the composition E KB ] Information processing method being stored in Do and providing for a device. 29. 複数のデバイスをリーフとして構成したヅリーのルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーヅリ一を 構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセットを 利用可能なデバイスにおいてのみ復号可能とした有効化キープ口ック (EKB) をデバイスに提供する構成を持つシステムにおける情報処理方法であり、 前記有効化キーブロック (EKB) は、 前記キーヅリ一の部分ヅリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キ一プロヅク (サブ E KB)の合成 EKBとして構成され、 該合成 E KB内に含まれる複数のキー ·デ一夕の各々が固定長のデータフィ一ル ド内に格納されてデバイスに提供することを特徴とする情報処理方法。
- 303 0. The above-mentioned subtree, It is classified based on a category, Category - Enti It is category Tree managed with a tee. the above-mentioned sub validation keeping lock (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to Category 1 which is set and self manages. , -- it can process based on a Was done key It is generated as EKB. Key issue center (KD C) Set. Said category. 'entity generates. It was substitute Based on E KB, it is usable common to a plurality of Category Lolli. It is referred to as E KB. Composition of The Claim generating E KB Information processing method given in 29. 3 0. 前記サブツリーは、 カテゴリに基づいて区分され、 カテゴリ ·ェンティ ティによって管理されるカテゴリヅリーであり、 前記サブ有効化キープロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリヅリ一に属するノードまたはリーフに対応付け られたキーに基づいて処理可能な EKBとして生成され、 キー発行センター (KD C) において、 前記カテゴリ ' エンティティの生成し たサブ E KBに基づいて、 複数のカテゴリッリーに共通に使用可能な E KBとし ての合成 E KBを生成することを特徴とする請求項 29に記載の情報処理方法。
- 313 1. Above-mentioned Sub Validation Key Block (Substitute EKB) Each, respectively -- original Al Gorism and 1 block of sub validation with original one key' De evening length (substitute EKB) As -- it is constituted -- key issue center (KD C) it sets to the generation processing of composition E KB based on said substitute E KB -- composition E KB -- Construct Each of key and data in To substitute EKB is stored in fixed-length De 1 taffy 1 Rudo. Information processing method given in Claim 29 performing processing. 3 1. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキー ' デ一夕長を持つサブ有効化キ一ブロック (サブ EKB) として構成され、 キー発行センター (KD C) は、 前記サブ E KBに基づく合成 E KBの生成処理において、 合成 E KBを構成す るサブ EKB内のキー · データの各々を固定長のデ一タフィ一ルド内に格納する 処理を実行することを特徴とする請求項 29に記載の情報処理方法。
- 32It is low rank A about the node key set up corresponding to each node which constitutes above-mentioned validation 1block (EKB) and above-mentioned Keatuli 1. Cryptographic key data enciphered using 1 Doki 1 or a low rank leaf key, one or more cryptographic key data each stored in said validation keeping mouth Dug (E KB) The node of the right-and-left position of the low rank of a node position, or cryptographic key data of a leaf position It is a statement to Claim 29 generating as composition containing the tag in which existence is shown. Information processing method. 32. 前記有効化キ一ブロック (EKB) は、 前記キーツリ一を構成する各ノードに対応して設定されるノードキーを下位ノ 一ドキ一または下位リーフキーを用いて暗号化した暗号化キーデータと、 前記有効化キープ口ヅク(E KB)に格納された 1以上の暗号化キーデータ各々 のノード位置の下位の左右位置のノードまたはリーフ位置の暗号化キーデータの 有無を示すタグを含む構成として生成することを特徴とする請求項 29に記載の 情報処理方法。
- 33The above-mentioned validation key block (EKB) the end node or leaf which can decode the validation key block (EKB) -- the lowest Choose the path which constitutes the simplified tree which was used as the stage, and omit an unnecessary node. By It is dark about the key corresponding to the node or leaf of reconstruction hierarchy Tree reconstructed. To Claim 29 generating as composition which it has as item-ized key data Information processing method of a statement. 33. 前記有効化キーブロック (EKB) は、 該有効化キーブロック (EKB) を復号可能な末端ノードまたはリーフを最下 段とした簡略化したツリーを構成するパスを選択して不要ノードを省略すること により再構築される再構築階層ヅリーのノードまたはリーフに対応するキーを暗 号化キーデータとして有する構成として生成することを特徴とする請求項 29に 記載の情報処理方法。
- 34It is Keatuli 1 about a plurality of cryptographic key data contained in each of said composition E KB and a plurality of substitutes E K B. Claim 2 re-arranging and generating according to the node which can be set, or a leaf position Information processing method given in 9. 34. 前記合成 E KBは、 複数のサブ E K Bの各々に含まれる複数の暗号化キーデータを、 キーツリ一に おけるノードまたはリーフ位置に応じて再配列して生成することを特徴とする請 求項 2 9に記載の情報処理方法。
- 353 5 . From Route of Tree Which Constituted a Plurality of Devices as a Leaf to Leaf Up Route on Path, A node and key tree which matched 1 with the leaf respectively It constitutes, The path which constitutes the 1 Tree is chosen, and it is based on the low rank key on a selection path. It has encryption processed data of a higher rank key, Node Keyset corresponding to the above-mentioned selection path Set to the device which can use A. 1 block (E K B) of validation which accepted and whose decoding it enabled It is validation keeping lock (E K B) generation processing in a system with the composition with which a device is provided Computer - Computer and program made to run on a system It is the recorded program recording medium, It decodes in each of Subtitled 1 set up as partial Rie of above-mentioned computer and program, and above-mentioned Key ring 1. 1 block of sub validation which can be processed (substitute E K B) Compositing process step, It is fixed-length data Feel about each of a plurality of key and data contained in composition E K B. Program recording medium having Step stored in Do. 3 5 . 複数のデバイスをリーフとして構成したヅリーのルートからリーフま でのパス上のルート、 ノード、 およびリーフに各々キ一を対応付けたキーツリー を構成し、 該キ一ヅリーを構成するパスを選択して選択パス上の下位キーによる 上位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ ト を利用可能なデバイスにおいてのみ復号可能とした有効化キ一ブロック( E K B ) をデバイスに提供する構成を持つシステムにおける有効化キープロック( E K B ) 生成処理をコンピュータ · システム上で実行せしめるコンピュータ · プログラム を記録したプログラム記録媒体であって、 前記コンピュータ · プログラムは、 前記キーヅリ一の部分ッリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キ一ブロック (サブ E K B ) の合成処理ステップと、 合成 E K B内に含まれる複数のキー ·データの各々を固定長のデータフィール ド内に格納するステヅプと、 を有することを特徴とするプログラム記録媒体。
- 363 6 . From Route of Tree Which Constituted a Plurality of Devices as a Leaf to Leaf Route on Path, A node and 1 tree which matched the key with the leaf respectively It constitutes, the path which constitutes the key tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A It is an information processing system with the composition which provides Depice with 1 block of validation (E K B) whose decoding was enabled only in the device which can be used, The above-mentioned validation key block (E K B) It decodes in each of Subtitled 1 set up as partial Rie of above-mentioned Keatuli 1. It is constituted as composition E K B of sub validation keeping D Dug (substitute E K B) which can be processed, Key in the each sub validation Gyi 1-block (substitute E K B) which and it stores Arrangement is held, [ composition ] and -- corresponding to each substitute E K B -- the data length of a sub E K B storing field -- Information processing Si having the composition which called and added one sub E K B discernment De evening Stem. 3 6 . 複数のデバイスをリーフとして構成したヅリーのルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキ一ツリーを 構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キ一ブロック ( E K B ) をデパイスに提供する構成を持つ情報処理システムであり、 前記有効化キーブロック (E K B ) は、 前記キーツリ一の部分ッリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キープ Dヅク (サブ E K B )の合成 E K Bとして構成され、 該合成 E K Bは、 格納する各サブ有効化ギ一ブロック (サブ E K B ) 内のキー 配列を保持し、 かつ、 各サブ E K Bに対応してサブ E K B格納領域のデータ長お よびサブ E K B識別デ一夕を付加した構成を有することを特徴とする情報処理シ ステム。
- 37Above-mentioned Subtitled 1, It is classified based on a category, Category - Enti It is a category tree managed with a tee. 1 block of the above-mentioned sub validation (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to Category Lolli which is set and self manages. , -- it can process based on a Was done key Are generated as E K B. Key issue center 1. (KD C) It sets, The above-mentioned category - entity generates. It was substitute It is based on E KB, It is usable common to a plurality of Category 1. It is referred to as E KB. Composition of The Claim being adapted to generate E KB Information given in 3 6 Processing system. 37. 前記サブヅリ一は、 カテゴリに基づいて区分され、 カテゴリ ·ェンティ ティによって管理されるカテゴリツリーであり、 前記サブ有効化キ一ブロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリッリーに属するノードまたはリーフに対応付け られたキーに基づいて処理可能な E K Bとして生成され、 キー発行センタ一 (KD C) において、 前記カテゴリ · エンティティの生成し たサブ E KBに基づいて、 複数のカテゴリヅリ一に共通に使用可能な E KBとし ての合成 E KBを生成する構成であることを特徴とする請求項 3 6に記載の情報 処理システム。
- 38said 1 block of sub validation (substitute EKB) Al original with each and each Sub validation key block with Gorism and original key' data length (substitute EKB) As -- information processing system given in Claim 36 constituting. 38. 前記サブ有効化キ一ブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキー 'データ長を持つサブ有効化キーブロック (サブ EKB) として構成されていることを特徴とする請求項 36に記載の情報処理システム。
- 393 9. Above-mentioned Subtitled 1, It is classified based on a category, Category ' Enti It is Category Lolli 1 managed with a tee. 1 block of the above-mentioned sub validation (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to Category Lolli which is set and self manages. , -- it can process based on a Was done key Are generated as E K B. Said composition. Each substitute in EKB Said substitute stored corresponding to E KB E KB discernment De One evening, Node which is an identifier of a node which constitutes category Tree It is I D. Claim by which it is characterized Information processing system given in 36. 3 9. 前記サブヅリ一は、 カテゴリに基づいて区分され、 カテゴリ ' ェンティ ティによって管理されるカテゴリッリ一であり、 前記サブ有効化キ一ブロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリッリーに属するノードまたはリーフに対応付け られたキーに基づいて処理可能な E K Bとして生成され、 前記合成 E KB内の各サブ E KBに対応して格納される前記サブ E KB識別デ 一夕は、 カテゴリヅリーを構成するノードの識別子であるノード I Dであること を特徴とする請求項 36に記載の情報処理システム。
- 40Each of sub validation key block (substitute EKB) stored in the above-mentioned composition E KB, It is a low rank node about the node key set up corresponding to each node which constitutes a key tree. Encryption 1 data enciphered using the key or the low rank leaf key, the node of the right-and-left position of the low rank of the node position of each cryptographic key data of said, or Li 1 It is the composition containing evening A which shows the existence of the cryptographic key data of a Off position. Claim 3 Information processing system given in 6. 40. 前記合成 E KBに格納されるサブ有効化キーブロック (サブ EKB) の 各々は、 キーツリーを構成する各ノードに対応して設定されるノードキーを下位ノード キーまたは下位リーフキーを用いて暗号化した暗号化キ一データと、 前記暗号化キーデータ各々のノード位置の下位の左右位置のノードまたはリ一 フ位置の暗号化キーデータの有無を示す夕グを含む構成であることを特徴とする 請求項 3 6に記載の情報処理システム。
- 41Each of sub validation key block (substitute EKB) stored in the above-mentioned composition E KB, the end node or leaf which can decode the substitute EK B was used as the lowest stage -- it simplified Choose the path which constitutes Tree and omit an unnecessary node. It is reconstructed. Let the key corresponding to the node or leaf of reconstruction hierarchy A dragon 1 be cryptographic key data. Information processing system given in Claim 36 carrying out Have. 41. 前記合成 E KBに格納されるサブ有効化キーブロック (サブ EKB) の 各々は、 該サブ E K Bを復号可能な末端ノードまたはリーフを最下段とした簡略化した ヅリーを構成するパスを選択して不要ノードを省略することにより再構築される 再構築階層ヅリ一のノードまたはリーフに対応するキーを暗号化キーデータとし て有することを特徴とする請求項 3 6に記載の情報処理システム。
- 42To Category Lolli 1 as subTree classified based on the category Configuration is carried out, From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on the path of until, Keatuli which matched the each key with the node and the leaf -- constituting -- The path which constitutes the key tree is chosen and it is to the low rank key on a selection path. At least a To top has encryption processed data of a key, Node Keyset corresponding to the above-mentioned selection path It is the information recording medium which stored validation keeping mouth A (E K B) whose decoding was enabled only in the device which can use A, It decodes in each of Sabilli 1 set up as partial A tree 1 of above-mentioned Key ring 1. 1 block of sub validation which can be processed (substitute EKB) Composition E KB is stored, this Synthesis corresponding to each substitute E KB contained in Formation E KB -- the one De evening length of a sub E KB storing field -- Information storage intermediation having the composition which called and stored sub E KB identification data The body. 42. カテゴリに基づいて区分されたサブヅリーとしてのカテゴリッリ一によ り構成され、 複数のデバイスをリーフとして構成したヅリーのルートからリーフ までのパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーツリ —を構成し、 該キーツリーを構成するパスを選択して選択パス上の下位キーによ る上位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを利用可能なデバイスにおいてのみ復号可能とした有効化キープ口ック (E K B) を格納した情報記録媒体であり、 前記キーヅリ一の部分ッリ一として設定されるサブッリ一の各々において復号 処理可能なサブ有効化キ一ブロック (サブ EKB) の合成 E KBを格納し、 該合 成 E KB内に含まれる各サブ E KBに対応してサブ E KB格納領域のデ一夕長お よびサブ E KB識別データを格納した構成を有することを特徴とする情報記録媒 体。
- 43said sub validation key block (substitute EKB) Al original with each and each Sub validation key block with Gorism and original key' data length (substitute EKB) As -- information recording medium given in Claim 42 constituting. 43. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自のアル ゴリズム、 独自のキー 'データ長を持つサブ有効化キーブロック (サブ EKB) として構成されていることを特徴とする請求項 42に記載の情報記録媒体。
- 44From the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Route on a path, A node and key Tree which matched the key with the leaf respectively It constitutes, the path which constitutes the key Tree is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A It is an information processing method in a system with the composition which provides a device with validation key block (EKB) whose decoding was enabled only in the device which can be used, It decodes in each of Subtitled 1 set up as partial Tree of the above-mentioned validation key block (EKB) and above-mentioned 1 A dragon 1. It is constituted as composition E KB of sub validation keeping mouth Dug (substitute E KB) which can be processed, The 1 block of each sub validation which and it stores (substitute EKB) Inner key Arrangement is held, [ composition ] and -- corresponding to each substitute E KB -- the data length of a sub E KB storing field -- as composition E K B with the composition which called and added one sub E KB discernment De evening -- a device -- Offer Offering information processing method. 44. 複数のデバイスをリーフとして構成したヅリ一のルートからリーフまで のパス上のルート、 ノード、 およびリーフに各々キーを対応付けたキーヅリーを 構成し、 該キーヅリーを構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック (EKB) をデバイスに提供する構成を持つシステムにおける情報処理方法であり、 前記有効化キーブロック (EKB) は、 前記キ一ヅリ一の部分ヅリーとして設定されるサブヅリ一の各々において復号 処理可能なサブ有効化キープ口ヅク (サブ E KB)の合成 E KBとして構成され、 該合成 E KBは、 格納する各サブ有効化キ一ブロック (サブ EKB) 内のキー 配列を保持し、 かつ、 各サブ E KBに対応してサブ E KB格納領域のデータ長お よびサブ E KB識別デ一夕を付加した構成を持つ合成 E K Bとしてデバイスに提 供することを特徴とする情報処理方法。
- 45Above-mentioned Subtitled 1, It is classified based on a category, Category - Enti It is category Tree managed with a tee. the above-mentioned sub validation key block (sub EKB) Is the above-mentioned category. 'entity Match with a node or a leaf belonging to category Tree which is set and self manages. , -- it can process based on a Was done key Are generated as E KB. Key issue center. (KD C) It sets, Said category ' An entity generates. It was substitute Based on E KB, it is usable common to a plurality of Category Lolli 1. It is referred to as E KB. Composition of The Claim generating E KB Information processing method given in 44. 45. 前記サブヅリ一は、 カテゴリに基づいて区分され、 カテゴリ · ェンティ ティによって管理されるカテゴリヅリーであり、 前記サブ有効化キーブロック (サブ EKB) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリヅリーに属するノードまたはリーフに対応付け られたキーに基づいて処理可能な E KBとして生成され、 キー発行センター (KD C) において、 前記カテゴリ ' エンティティの生成し たサブ E KBに基づいて、 複数のカテゴリッリ一に共通に使用可能な E KBとし ての合成 E KBを生成することを特徴とする請求項 44に記載の情報処理方法。
- 46said sub validation key block (substitute EKB) . Al original with each and each Sub validation key block with Gorism and original key' data length (substitute EKB) As -- information processing method given in Claim 44 constituting. 46. 前記サブ有効化キーブロック (サブ EKB) の各々は、 各々独自の.アル ゴリズム、 独自のキー 'データ長を持つサブ有効化キーブロック (サブ EKB) として構成されることを特徴とする請求項 44に記載の情報処理方法。
- 47The above-mentioned subtree, It is classified based on a category, Category ' Enti It is a category tree managed with a tee. the above-mentioned sub validation key block (sub E K B) Is the above-mentioned category. 'entity Match with A 1 Do or a leaf belonging to Category Lolli 1 which is set and self manages. , -- it can process based on Killed 1 Are generated as E K B. Each substitute in said composition E K B. Said substitute stored corresponding to E K B E K B discernment De One evening, Node which is an identifier of a node which constitutes Category 1 It is I D. Claim by which it is characterized Information processing method given in 4 4. 47. 前記サブツリーは、 カテゴリに基づいて区分され、 カテゴリ ' ェンティ ティによって管理されるカテゴリツリーであり、 前記サブ有効化キーブロック (サブ E K B ) は、 前記カテゴリ 'エンティティ において自己の管理するカテゴリッリ一に属するノ一ドまたはリーフに対応付け られたキ一に基づいて処理可能な E K Bとして生成され、 前記合成 E K B内の各サブ E K Bに対応して格納される前記サブ E K B識別デ 一夕は、 カテゴリヅリ一を構成するノードの識別子であるノード I Dであること を特徴とする請求項 4 4に記載の情報処理方法。
- 484 8 . Sub Validation Key Block Stored in the Above-mentioned Composition E K B (Substitute E K B) Each, It is a low rank node about the node key set up corresponding to each node which constitutes Keatuli 1. Cryptographic key data enciphered using the key or the low rank leaf key, the node of the right-and-left position of the low rank of the node position of each cryptographic key data of said, or Li 1 Claim 4 containing evening A which shows the existence of the cryptographic key data of a Off position Information processing method given in 4. 4 8 . 前記合成 E K Bに格納されるサブ有効化キーブロック (サブ E K B ) の 各々は、 キーツリ一を構成する各ノードに対応して設定されるノードキーを下位ノード キーまたは下位リーフキーを用いて暗号化した暗号化キーデータと、 前記暗号化キーデータ各々のノード位置の下位の左右位置のノードまたはリ一 フ位置の暗号化キーデータの有無を示す夕グを含むことを特徴とする請求項 4 4 に記載の情報処理方法。
- 494 9 . Sub Validation Key Block Stored in the Above-mentioned Composition E K B (Substitute E K B) Each, the end node or leaf which can decode the substitute E K B was used as the lowest stage -- it simplified Choose the path which constitutes A dragon 1 and omit an unnecessary node. It is reconstructed. Let the key corresponding to the node or leaf of reconstruction hierarchy Tree be cryptographic key data. Information processing method given in Claim 4 carrying out Have. 4 9 . 前記合成 E K Bに格納されるサブ有効化キーブロック (サブ E K B ) の 各々は、 該サブ E K Bを復号可能な末端ノードまたはリーフを最下段とした簡略化した ヅリ一を構成するパスを選択して不要ノードを省略することにより再構築される 再構築階層ヅリーのノードまたはリーフに対応するキーを暗号化キーデータとし て有することを特徴とする請求項 4 に記載の情報処理方法。
- 505 0 . From Le 1 A of Tree Which Constituted a Plurality of Devices as a Leaf to Leaf Route on Path, A node and key Tree which matched 1 with the leaf respectively It constitutes, the path which constitutes the Key ring 1 is chosen and it is based on the low rank key on a selection path -- the upper -- about -- having encryption processed data of a key Node Keyset corresponding to the above-mentioned selection path A Set to the device which can be used. Validation key block which accepted and whose decoding it enabled (E K B) It is validation keeping lock (E K B) generation processing in a system with the composition with which a device is provided Computer - Computer and program made to run on a system It is the recorded program recording medium, It decodes in each of subTree set up as partial Tree of above-mentioned computer and program, and above-mentioned Keatuli 1. Sub validation key block which can be processed (substitute EKB) Selection step, The program recording medium having a step which adds the data length of a sub E KB storing field, and one sub E K B discernment De evening corresponding to each selection sub E KB. 5 0 . 複数のデバイスをリーフとして構成したヅリーのル一トからリーフまで のパス上のルート、 ノード、 およびリーフに各々キ一を対応付けたキーヅリーを 構成し、 該キーヅリ一を構成するパスを選択して選択パス上の下位キーによる上 位キーの暗号化処理データを有し、 前記選択パスに対応するノードキーセッ トを 利用可能なデバイスにおいてのみ復号可能とした有効化キーブロック ( E K B ) をデバイスに提供する構成を持つシステムにおける有効化キープロック( E K B ) 生成処理をコンピュータ · システム上で実行せしめるコンピュータ · プログラム を記録したプログラム記録媒体であって、 前記コンピュータ · プログラムは、 前記キーツリ一の部分ヅリーとして設定されるサブヅリーの各々において復号 処理可能なサブ有効化キーブロック (サブ EKB) の選択ステップと、 各選択サブ E KB.に対応してサブ E KB格納領域のデータ長およびサブ E K B 識別デ一夕を付加するステップと、 を有することを特徴とするプログラム記録媒体。
Independent claims48
543 paragraphs, as filed
Specification
The information processing system And method
Technical field
the present invention, an information processing system, an information processing method, an information recording medium, and A it is related with a log rum recording medium -- especially -- various data, such as contents, -- specific just you It is related with the distribution system and method accompanied by scrambling with which THE is provided. especially -- tree (A tree 1) the hierarchical key distribution method of structure is used -- key Brods generated according to the distribution device Use The. for example, it contents-key-distributes as a cryptographic key of contents, and is it is -- the information processing system which makes it possible to, keep various kinds of safeties in addition to this, and information place It is related with Rational method, an information recording medium, and a program recording medium. Background art
These days, a game program, one voice De evening, image data, etc. and various Software One evening (Hereinafter, these are called contents (Content)) In Turnet Those, such as A Circulation through the storage of Network or D V D, C D, etc. which can be circulated is the peak. It is becoming Hmm. P C (Personal Computer) which these circulation contents and a user own, a game machine machine -- Wear of data reception or a storage Record De in the record playback apparatus which arrival is made and played or is attached to P C etc. it is stored in vice, for example, a memory card, a hard disk, etc. -- from a storing medium It is used by new playback.
In information machines and equipment, such as a video game instrument and P C, It is Netsu about circulation contents. Network D V D in order to receive, C interface for accessing D etc. it has -- the control means which is further needed for reproduction of contents, a program, and one De evening It has R A M, R O M, etc. which are used as a memory field.
Various contents, such as music data, one picture De evening, or a program, reproduction The user directions from main parts of information machines and equipment, such as a game machine machine used as apparatus, and P C, and Burning is called from a storage by directions of the user through the connected input means -- being reproduced through the main part of information machines and equipment or the connected display, a speaker, etc. To.
Sov of a game program, music data, image data, etc. and many Toware' Conte The right of distribution, etc. are held by Tennis and the general target at the maker and a vender. therefore, This distribution of Content of Re and others is faced -- fixed use restrictions, i.e., a regular user, it only receives -- Software is licensed -- reproduction without permission, etc. are not performed It is common to take the composition which carries out for obtaining, namely, took security into consideration. One technique of realizing the use restrictions to a user is an encryption place of distribution Content. It is Reason. Namely, for example, in evening 1 A net While distributing various Content, such as voice data enciphered via A etc., image data, and a game program, regular U as opposed to 1 the Is and those that were checked -- distributed encryption Content -- Decrypt It is the composition which gives Means, i.e., a decoding key.
Encryption data and decoding De 1 which can be used by decryption processing in a predetermined procedure Evening (Plaintext) It can return. an encryption key is used for encryption processing of such information -- the data encryption which uses a decryption key for decryption processing, and a decoding method are well learned from the former ing.
Various kinds in the mode of data encryption and the decoding method using an encryption key and a decryption key The method currently called what is called a common key encryptosystem-ized method as the one example although it is is Ah. To. decoding of a common key encryptosystem-ized method, the encryption key used for encryption processing of data, and data the common key which uses for these encryption processings and decryption the decryption key used for-izing at a user regular as a common thing is given -- data access by an inaccurate user without a key It eliminates. It is D E S (data code standard: Deta encryption standard) to the typical method of this method. It is.<sub>0</sub>
The encryption key used for above-mentioned encryption processing and decryption, and decryption key, for example, a certain The, On the other hand based on Seward etc., a hash function etc. can be obtained with the application of a tropism function. To. Seki which becomes very difficult [ a tropism function ] for asking for an input conversely from the output on the other hand It is a number. For example, on the other hand, a tropism function is applied by considering as an input the password which the user decided. An encryption key and a decryption key are generated based on The and its output. It is such. Path which is the original data conversely from the encryption key produced by carrying out, and a decryption key The substance top of asking for a word becomes impossible.
It is used when decoding with processing with the encryption key used when enciphering. The method which made processing of a decryption key to carry out a different A cargo rhythm is what is called public-key-encryption-ization. It is a method called a method. Public-key-encryption-ized method, An unspecified user is usable. It is the method of using a public key. Encryption document to a specific individual, The specific individual Encryption processing is performed using a published public key. Document enciphered with the public key It is decoding processing only by the secret key corresponding to the public key used for the encryption processing. It becomes possible. Since only the individual who published the secret key and the public key owns, it is the public presentation. Only an individual with a secret key can decode the document enciphered with the key. In the typical thing of a public-key-encryption-ized method (Rivest-Shamir-Adleman) a R S A code is Ah. To. By using such a cipher system, it is regular you about encryption contents. The system whose decoding is enabled only to THE becomes possible.
Content is enciphered in the above Content distribution systems, and it is to a user. Network, or it stores in recording media, such as D V D and C D, and provides -- encryption Co the composition which provides only a just user with the contents key which decodes Balance -- many -- Adoption is carried out. in order to prevent the unjust copy of the contents key itself, etc. -- Maintenance 1 is enciphered and it provides for a just user -- the decryption key which only a just user has -- business the composition which is, decodes encryption Content key and makes a contents key usable -- Offer The proposal is carried out.
the judgment of whether to be a just user, and general, for example, Content, sender it sets between user devices with a certain content provider -- contents -- or -- It becomes possible by performing attestation processing before distribution of Content key. general are . it sets to attestation processing -- while checking a partner -- effective S only at the communication Session 1 generated when Shion key was generated and attestation was materialized -- business It is, and data, for example, Content, or a contents key is enciphered, and Line in communication obtaining -- . The public key system was used with the mutual recognition which used the common key encryption system for the authentic method. It is System Y, if it sets to the attestation using a common key although there is an authentic method. Key common to Do It is inconvenient to necessity in the cases, such as an update process. In a public key system, the amount of memories which needs calculation load large again also becomes large, and it is such processing to each device. It cannot say establishing a means as desirable composition. The indication of an invention
This for which it depends on the mutual recognition processing between the sender of the one above De evenings, and a receiving person in the present invention there is nothing and it only receives a just user -- it makes it possible to transmit data safely Along with the subtree which made hierarchical key distribution A dragon 1 the category unit, i.e., Kate, Gori lily is formed -- it is application within a plurality of category Tree (decoding processing) Possible encryption The composition which uses keeping mouth Dug is proposed.
In one or more selected category trees, it is an encryption key day which can be decoded. Validation key block (EKB) which is an evening block is generated, and it is to each category tree. In the device which belongs while it is usable in common, it is which category Tree. Processing possibility of, That is, the E KB type definition list in which it is shown whether it can decode is used. By things, the information processing system and information processing method which enabled the increase in efficiency of EKB generation and management processing, an information recording medium, and a program recording medium are provided. It is considered as the object.
The side of The 1 of the present invention,
Path from Le 1 A of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Upper route, A node and the key tree which matched the key with the leaf respectively are constituted, Higher rank key choose the path which constitutes the key tree and according to the low rank key on a selection path It has encryption processed data, Node Keyset corresponding to the above-mentioned selection path Use of A is possible. are . Validation key block whose decoding was enabled only in the device (EKB) Debye It is an information processing system with the composition with which A is provided,
As opposed to key issue center (KD C) which generates validation key block (EKB) The EKB Request evening which requires generation of The EKB,
the E KB generation demand of The 1 as a E KB generation demand containing a generated route key -- or
Le 1 crested ibis in 1 issue center (KD C) -- 1 generation and the generation roux -- crested ibis 1 E KB generation demand of The 2 which requires the EKB generation to include as a E K B generation demand of as opposed to key issue center (KD C) for either -- output Carry out.
It is in the information processing system having the composition which performs E KB generation which includes a receiving route key or a generation route key according to reception of key issue center (KD C), the E KB generation demand of above-mentioned The 1, or a E KB generation demand of above-mentioned The 2. In one embodiment of an information processing system of the present invention, it is the above-mentioned key tree, It is classified based on a category, Substitute managed by category' entity It is the composition which carries out two or more owners of the category tree as Tree. Above EKB Request evening An EKB type identifier and identification data of category Tree in which E KB processing is possible It matched. It is based on a E KB type definition list. A E KB type identifier is chosen, A selection E KB type identifier is included. It is the above-mentioned The about a E KB generation demand. A E KB generation demand or above-mentioned The of 1 It is the above-mentioned key issue center as an EKB generation demand of 2. (KD C) It receives and is an output. It is the composition to carry out.
it sets in the one embodiment of the information processing system of the present invention -- the above-mentioned EKB Rique the A evening -- memory measure, Or Netsai on Network which can be perused It is the composition which chooses a E K B type identifier based on the E K B type definition list acquired from A. It is considered as the feature.
it sets in the one embodiment of the information processing system of the present invention -- the above-mentioned E KB type The identification data of Category 1 which a definition list can E K B process, and Category 1 It is node I D which is an identifier of a node.
it sets in the one embodiment of the information processing system of the present invention -- the above-mentioned EKB type composition including the explanation about the device which belongs to a definition list at a category tree -- Ah It is characterized by To.
The side of The 2 of the present invention,
Path from the route of A tree 1 which constituted a plurality of Depice as a leaf to a leaf Upper Le 1 A, A node and the key tree which matched the key with the leaf respectively are constituted, Higher rank key choose the path which constitutes the key tree and according to the low rank key on a selection path It has encryption processed data, Use of A 1 Dokey set corresponding to the above-mentioned selection path is possible. are . Validation key block whose decoding was enabled only in the device (EKB) Debye It is an information processing system with the composition with which A is provided,
Above-mentioned Key ring 1, It is classified based on a category, Category To - entity It is the composition which carries out two or more owners of the category Tree as subTree by which intermediary management is carried out. 1 block of validation (EKB) Key issue center to generate (KD C) Is Validation based on a demand of an EKB requester which is a demand entity of EKB generation. Key block (EKB) In generation, Validation key block to generate. (EKB) Category Tree which can be decoded is managed. It is each power to one or more category entities. In a Age tree, he is a substitute who can process. A generation demand of E KB is outputted, Category. Sub validation key block received from . Entity (sub EKB) It can be based and can process in one or more category trees. It is Special about having the composition which generates E KB. It is in an information processing system considered as a mark.
it sets in the one embodiment of the information processing system of the present invention -- above-mentioned key issue Seng Tarr (KD C) E KB type identifier and category Tree in which E KB processing is possible It has the E KB type definition list which matched identification data, E Require generation of KB. It is Included during the E KB generation demand received from the EKB Request evening which is an entity to carry out. It is a category by the search of a E KB evening eve definition list based on a To be E KB type identifier. The identification data of Tree is extracted, It corresponds to the identification data of extracted Category 1. Based on substitute E KB whom one or more category . entities to carry out generated, EKB usable in common is generated to category Tree set as the EKB type definition list. It is the composition provide by carrying out.
it sets in the one embodiment of the information processing system of the present invention -- above-mentioned key issue Seng Category' entity which received the sub EKB generation demand from evening 1 (KD C), matched with the node or leaf belonging to category Tree of self to manage It is based on 1 and is sub validation keeping mouth Dug as EKB which can be processed. (substitute EKB) It is the composition to generate.
In one embodiment of the information processing system of the present invention, it is the above-mentioned key Tree, two or more steps of roux Tori 1 are constituted by the highest rung -- it links with the Lou Torri 1 directly Topre Bell Category Lolli, The connected with the lower berth of the Tap level and category Tree it is constituted by the Category tree -- the above-mentioned category' entity, Above-mentioned Totu Pre bell - [ SubCategory Lolli which stands in a row in the lower berth of A dragon 1, and the Tap level and Category 1 -- It manages, ] It is the Tap level ■ as a management entity of Category 1. Category The above-mentioned category and entity, Self manages. Top level - Substitute who stands in a row in the lower berth of Category 1, and the Tap level and Category Lolli 1 It corresponds to the node or leaf belonging to category Tree. It is Based on to the key set up. Sub validation key block as E KB in which Processing is possible (substitute EKB) It generates. It is composition.
The side of The 3 of the present invention,
Path from Le 1 A of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Upper route, A node and the key tree which matched the key with the leaf respectively are constituted, Higher rank key choose the path which constitutes the key tree and according to the low rank key on a selection path It has encryption processed data, A 1 Key set corresponding to the above-mentioned selection path Use of A is possible. are . Validation key block whose decoding was enabled only in the device (EKB) Debye It is an information processing method in a system with the composition with which A is provided,
As opposed to key issue center (KD C) which generates validation key block (EKB) The E KB Request evening which requires generation of The E KB,
the E KB generation demand of The 1 as a E KB generation demand containing a generated route key -- or
the route key generation in key issue center (KD C), and the generation roux -- crested ibis 1 E KB generation demand of The 2 which requires the EKB generation to include,
It is an output as a E K B generation demand of as opposed to key issue center (KD C) for whether it is Either. It carries out,
It is in the information processing method performing E KB generation which includes a receiving route key or a generation route key according to reception of key issue center (KD C), the E KB generation demand of above-mentioned The 1, or a E KB generation demand of above-mentioned The 2.
Further, It sets in the one embodiment of an information processing method of the present invention, The above-mentioned key tree is power. It is classified based on Age, Category Sub-mochi managed by - entity It is the composition which carries out two or more owners of Category 1 as Lee. Above A E KB requester, an EKB type identifier, and the identification data of category Tree in which E KB processing is possible are corresponded. It attached. It is based on a E KB type definition list. A E KB type identifier is chosen, Selection. A E KB type identifier is included. It is the above-mentioned The about a E KB generation demand. An EKB generation demand or the above of 1 It is the above-mentioned key issue center as the 2nd EKB generation demand. (KD C) It receives and outputs. It is characterized by things.
it sets in the one embodiment of the information processing method of the present invention -- the above-mentioned E KB requester A memory measure or Netsai on Network which can be perused A E KB type identifier is chosen based on the EKB type definition list acquired from A. it sets in the one embodiment of the information processing method of the present invention -- the above-mentioned E KB type definition The identification data of Category Lolli which a list can EKB process, and A of category Tree It is node I D which is an identifier of 1 Do.
it sets in the one embodiment of the information processing method of the present invention -- the above-mentioned E KB type definition This which is composition including the explanation about the device which belongs to a list at category Tree It is considered as the feature.
The side of The 4 of the present invention,
Path from Le 1 A of Tree which constituted a plurality of devices as a leaf to a leaf Upper route, 1 Tree which matched the key with the node and the leaf respectively is constituted, Higher rank key choose the path which constitutes the key tree and according to the low rank key on a selection path It has one encryption processing De evening, Node tree 1 Set corresponding to the above-mentioned selection path Use of A is possible. are . Validation key block whose decoding was enabled only in the device (EKB) Debye It is an information processing method in a system with the composition with which A is provided,
The above-mentioned key tree, It is classified based on a category, Category ' To an entity It is the composition which carries out two or more owners of Category 1 as a subtree therefore managed. validation key block (EKB) Key issue center to generate (KD C) Is E It is a demand entity of KB generation. Validation based on a demand of a E KB requester Keeping mouth Dug (EKB) In generation, Validation keeping mouth Dug to generate. (EKB) Category 1 which can be decoded is managed. It is each power to one or more category entities. In Tegory Lee, he is a substitute who can process. A generation demand of E KB is outputted, Category. Sub validation key block received from - Entity (sub EKB) It is based. It can process in one or more category Tree. It is in an information processing method generating E KB.
it sets in the one embodiment of the information processing method of the present invention -- the above-mentioned key issue Seng evening 1 (KD C), E Discernment of KB type identifier and category Tree in which E KB processing is possible It has the EKB type definition list which matched data, Generation of EKB is required. It is Category by the search of a E KB type definition list based on the E KB type identifier contained during the E KB generation demand received from the EKB Request evening which is an entity. -- Identification data is extracted, It is based on substitute E KB whom one or more category' entities corresponding to the identification data of extracted Category 1 generated, and is an EKB tie. It is the composition of generating and providing with E KB usable in common Category Lolli set as the A definition list.
it sets in the one embodiment of the information processing method of the present invention -- the category . entity which received the sub EKB generation demand from the above-mentioned key issue Seng evening 1 (KD C), self Key matched with the node or leaf belonging to category Tree to manage being based -- 1 block of sub validation as E KB which can be processed (substitute EKB) raw -- Formation is carried out.
it sets in the one embodiment of the information processing method of the present invention -- above-mentioned Key ring 1, the maximum -- two or more steps of roux Tori 1 are constituted by the upper row -- Top level linking directly to the route Tsu Lee Le Categoryllie, substitute connected with the lower berth of the Tap level and Category Lolli 1 it is constituted by the category tree -- the above-mentioned category' entity The, Above-mentioned top-level - It is the Tap level - as management Entity of Category 1. Category SubCategory 1 which stands in a row in the lower berth of Li 1 and the Tap level Category 1 It manages, The above-mentioned category' entity, Self manages. Top-level' Subcatere which stands in a row in the lower berth of Category 1 and the Tap level Category 1 It corresponds to the node or leaf belonging to Gori lily. It is based on the key set up and is a place. Sub validation keeping Rodzuk as E KB in which Reason is possible (substitute EKB) It generates. It is considered as the feature.
The side of The 5 of the present invention,
Path from the route of Rie which constituted a plurality of devices as a leaf to a leaf Upper route, Keatuli 1 which matched the key with the node and the leaf respectively is constituted, Higher rank key choose the path which constitutes the key Tree and according to the low rank key on a selection path It has encryption processing De 1 Tha, Use of Node tree 1 Setsu corresponding to the above-mentioned selection path is possible. are . Set to a device. Validation key block which accepted and whose decoding it enabled (EKB) Debye It is on computer and a system about the information processing in a system with the composition with which A is provided. It is the program recording medium which recorded the computer program made to run, and is Buddy. The, Above-mentioned computer and program,
The E KB generation demand of The 1 as a E KB generation demand containing a generated route key, Or the route key generation in key issue center 1 (KD C) and the generation route One E KB generation of the E KB generation demands of The 2 which requires the E K B generation containing a key Step which receives a demand,
Either of the E KB generation which includes the E KB generation including a receiving route key or generation of a route key, and a generation route key according to the kind of received E KB generation demand Step which performs processing alternatively,
It is in the Have(ing) program recording medium.
The side of The 6 of the present invention,
Path from the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Upper route, Key ring 1 which matched the key with the node and the leaf respectively is constituted, Higher rank key choose the path which constitutes the key tree and according to the low rank key on a selection path It has encryption processed data, Node Keyset corresponding to the above-mentioned selection path Use of A is possible. are . Set to a device. Validation keeping Rodzuk which accepted and whose decoding it enabled (EKB) Debye It is on a computer . system about the information processing in a system with the composition with which A is provided. It is the program recording medium which recorded the computer program made to run, and is Buddy. The, Above-mentioned computer and program,
E It is based on the E KB type identifier contained in KB generation demand, and is E KB type discernment. Child, E The step which extracts the identification data of category Tree from the E KB type definition list which matched the identification data of one or more category trees in which KB processing is possible, setting at each category Tree to one or more category . entities which manage category Tree corresponding to the identification data of extracted category Tree -- the substitute who can process -- an owner -- Effect-ized key block (substitute EKB) Step which outputs a generation demand, Sub validation key block received from category and an entity (substitute EKB) Steps which is based and generates E KB which can be processed in one or more category Tsu leap,
It is in the Have(ing) program recording medium.
The side of The 7 of the present invention,
Path from the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Upper route, 1 A dragon 1 which matched the key with the node and the leaf respectively is constituted, Higher rank key choose the path which constitutes the key tree and according to the low rank key on a selection path It has encryption processed data, Use of the A 1 Do key set corresponding to the above-mentioned selection path is possible. are . Validation key block whose decoding was enabled only in the device (EKB) Debye It is an information processing system with the composition with which A is provided,
The above-mentioned validation key block (EKB)
It decodes in each of Sabilli 1 set up as partial Tree of above-mentioned Key ring 1. It is constituted as composition E KB of sub validation keeping mouth Dug (substitute E KB) which can be processed, One De evening Feer of fixed length [ each / of a plurality of key and data contained in the composition E KB ] It is in the information processing system having the composition stored in Do.
In one embodiment of an information processing system of the present invention, it is the above-mentioned subTree, It is classified based on a category, Category Kate managed by entity It is Gori lily. the above-mentioned sub validation key block (sub EKB) Is the above-mentioned category. Li a node which belongs to category Tree of self to manage in - entity -- or -- It can process based on a key matched with a leaf. Are generated as E KB. Key. Issue center (KD C) It sets and is the above-mentioned category. Substitute whom 'entity generated It is based on E KB, It is usable common to a plurality of category Tree. Synthesis as E KB It is adapted to generate Formation E KB.
it sets in the one embodiment of the information processing system of the present invention -- the above-mentioned sub validation 1 block (substitute EKB) Each, respectively -- An original algorithm and original key' De -- sub validation key block with evening length (substitute EKB) As -- it is constituted -- key issue The Seng evening 1 (KD C) it sets to the generation processing of composition EKB based on the above-mentioned substitute EKB -- each of one key . De evening in substitute E KB who constitutes composition E KB -- fixed-length day taffy It is the composition of performing processing stored in - Red.
In one embodiment of the information processing system of the present invention, it is the above-mentioned composition E K B, It is low rank no about the node key set up corresponding to each node which constitutes the above-mentioned key tree. One encryption Kee de evening enciphered using Do key or a low rank leaf key, about one or more right and left of the low rank of the node position of each cryptographic key data stored in the above-mentioned composition E K B Composition containing the tag in which the existence of the node of Place or the cryptographic key data of a leaf position is shown It is characterized by a certain thing.
In one embodiment of the information processing system of the present invention, it is the above-mentioned composition E K B, Simplified Tsu which used as the lowest stage the end node or leaf which can decode the composition E K B The path which constitutes Lee is chosen and an unnecessary node is omitted. it is reconstructed -- re--- Use the key corresponding to the node or leaf of construction hierarchy Tree as cryptographic key data. It has.
a plurality of cryptographic key data contained in each of the above-mentioned composition E K B and a plurality of substitutes E K B in one embodiment of the information processing system of the present invention -- a key tree -- Have the composition which re-arranged and was generated according to the node or leaf position to kick. It is considered as the feature.
The side of The 8 of the present invention,
Category Tree as Subtitled 1 classified based on the category constitutes. It is carried out, From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on a path, It is a style about key Tree which matched the key with the node and the leaf respectively. It accomplishes, Higher rank choose the path which constitutes the key tree and according to the low rank key on a selection path It has encryption processed data of a key, Node Kisera corresponding to the above-mentioned selection path It is a profit about A. It is the information recording medium which stored validation keeping Rodzuk (E K B) whose decoding was enabled only in the device in which for is possible,
It decodes in each of Sabilli 1 set up as partial Rie of above-mentioned Keatuli 1. Composition E K B of 1 block of sub validation (substitute E K B) which can be processed is stored, This Synthesis Inside of the data field of fixed length [ each / of a plurality of key and data contained in Formation E K B ] It is in the information recording medium having the stored composition.
it sets in the one embodiment of the information recording medium of the present invention -- the above-mentioned sub validation keeping Lock (substitute EKB) Each, respectively -- an original algorithm and original key . data Sub validation key block with merit (substitute EKB) As -- it is constituted -- one key . De evening A storing field is the composition made into fixed length.
The side of The 9 of the present invention,
Path from the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Upper route, Key Tree which matched the key with the node and the leaf respectively is constituted, Higher rank key choose the path which constitutes the key Tree and according to the low rank key on a selection path It has encryption processed data, Node Keyset corresponding to the above-mentioned selection path Use of A is possible. are . Validation key block whose decoding was enabled only in the device (EKB) Debye It is an information processing method in a system with the composition with which A is provided,
The above-mentioned validation key block (EKB)
It decodes in each of Subtitled 1 set up as partial Tree of above-mentioned Keatuli 1. It is constituted as composition E KB of sub validation keeping mouth Dug (substitute EKB) which can be processed, Data Feel of fixed length [ each / of a plurality of key and data contained in the composition E KB ] It is in the information processing method being stored in Do and providing for a device. Further, It sets in the one embodiment of an information processing method of the present invention, Above-mentioned Subtitled 1 is classified based on power Age, Category category managed by 'entity It is Lily. the above-mentioned sub validation keeping mouth Dug (sub E KB) Is The above-mentioned category. A node or Lee who belongs to self Category Lolli to manage in . entity It can process based on 1 matched with Off. It is generated as EKB and is key issue. Center (KD C) It sets, The above-mentioned category. It is based on substitute EK B whom - entity generated, It is usable common to a plurality of category Tree. Composition as E KB E KB is generated.
it sets in the one embodiment of the information processing method of the present invention -- the above-mentioned sub validation keeping Lock (substitute EKB) Each, respectively -- an original algorithm and original 1 . data 1 block of sub validation with merit (substitute EKB) As -- it is constituted -- 1 issue Seng Evening 1 (KD C) It is fixed-length data phi about each of key and data in substitute E KB who constitutes composition E KB in the generation processing of composition E KB based on the above-mentioned substitute E KB. Processing stored in Rudo is performed. it sets in the one embodiment of the information processing method of the present invention -- the above-mentioned validation key Block (EKB), No set up corresponding to each node which constitutes above-mentioned Key ring 1 Encryption Kee de which enciphered Doki 1 using low rank Node tree 1 or a low rank leaf key One evening, one or more encryption 1 De stored in the above-mentioned validation key block (EKB) The node of the right-and-left position of the low rank of a A of each one evening 1 Do position, or cryptographic key of a leaf position It generates as composition containing the tag in which the existence of one De evening is shown.
it sets in the one embodiment of the information processing method of the present invention -- the above-mentioned validation key Block (EKB) the end node which can decode the validation key block (EKB) -- moreover -- choosing the path which constitutes simplified Tree which used the leaf as the lowest stage -- unnecessary node Omit. It is a pair to the node or leaf of reconstruction hierarchy Tree reconstructed. They are the feature and To about generating the key which carries out Response as composition which it has as cryptographic key data. To.
it sets in the one embodiment of the information processing method of the present invention -- the above-mentioned composition E KB -- double -- A plurality of cryptographic key data contained in each of substitute EKB of a number can be set to key Tree. According to a To node or a leaf position, it re-arranges and generates.
The 1 of the present invention The 0 sides,
Path from the route of Tree which constituted a plurality of devices as a leaf to a leaf Upper route, Key ring 1 which matched the key with the node and the leaf respectively is constituted, Higher rank key choose the path which constitutes the key tree and according to the low rank key on a selection path It has encryption processed data, Use of the node key set corresponding to the above-mentioned selection path is possible. are . Set to a device. Validation key block which accepted and whose decoding it enabled (EKB) Debye (EKB) Validation key block generation place in a system with the composition with which A is provided It is record about computer and the program which makes Reason perform on computer and a system. it is the program recording medium carried out -- the above-mentioned computer program,
It decodes in each of Subtitled 1 set up as partial Tree of above-mentioned Key ring 1. Sub validation key block which can be processed (substitute EKB) Compositing process step, It is fixed-length De 1 Tafil about each of a plurality of key and data contained in composition EKB. Step stored in Do,
It is in the Have(ing) program recording medium. The 1 of the present invention The side of 1,
Path from the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Upper route, A 1 Do and key Tree which matched the key with the leaf respectively are constituted, Higher rank key choose the path which constitutes the key tree and according to low rank 1 on a selection path It has encryption processed data, Node Keyset corresponding to the above-mentioned selection path Use of A is possible. are . Validation key block whose decoding was enabled only in the device (EKB) Debye It is an information processing system with the composition with which A is provided,
The above-mentioned validation key block (EKB)
It decodes in each of Subtitled 1 set up as partial Tree of above-mentioned Key ring 1. It is constituted as composition E KB of sub validation keeping mouth Dug (substitute E KB) which can be processed, Each sub validation key block which stores the composition E KB (substitute EKB) Inner key Arrangement is held, and -- corresponding to each substitute E KB -- the data length of a sub E KB storing field -- Information processing Si having the composition which called and added one sub E K B discernment De evening It is in a stem.
In one embodiment of an information processing system of the present invention, it is above-mentioned Subtitled 1, It is classified based on a category, Category Kate managed by - entity It is Gori tree. the above-mentioned sub validation key block (sub EKB) Is the above-mentioned category. Li - a node which belongs to a category tree of self to manage in an entity -- or -- It can process based on a key matched with a leaf. Are generated as EKB. Key. Issue center 1 (KD C) It sets and is the above-mentioned category. Substitute whom 'entity generated It is based on E KB, It is usable common to a plurality of category Tree. Synthesis as E KB It is adapted to generate Formation E KB.
it sets in the one embodiment of the information processing system of the present invention -- the above-mentioned sub validation 1 block (substitute EKB) Each, They are an original algorithm and original key . respectively. De -- Sub validation keeping Rodzuk with evening length (substitute EKB) It is constituted by carrying out. It is considered as the feature.
In one embodiment of an information processing system of the present invention, it is the above-mentioned subTree, It is classified based on a category, Category Kate managed by - entity It is Gori lily. the above-mentioned sub validation key block (sub EKB) Is the above-mentioned category. Li a node which belongs to self Category Lolli to manage in - entity -- or -- It can process based on 1 matched with a leaf. Are generated as E KB. Above. Composition Each substitute in E KB The above-mentioned substitute stored corresponding to E KB E KB identification data, Node which is an identifier of a node which constitutes a category tree It is the feature about it being I D. It carries out.
it sets in the one embodiment of the information processing system of the present invention -- the above-mentioned composition E KB Sub validation keeping lock stored (substitute EKB) Each, Key Tree is constituted. They are a low rank node key or low rank Li 1 about the node key set up corresponding to each node to carry out. Cryptographic key data enciphered using Fukyu, A of each one above-mentioned encryption Kee de evening Existence of the node of the right-and-left position of the low rank of a 1 Do position, or the cryptographic key data of a leaf position It is the composition containing the shown tag.
it sets in the one embodiment of the information processing system of the present invention -- the above-mentioned composition E KB Sub validation key block stored (substitute EKB) Each, It is Recovery about the substitute EKB. The which constitutes simplified Tree which used as the lowest stage the end node in which an item is possible, or Li 1 Foss is chosen and an unnecessary node is omitted. Reconstruction hierarchy Tree reconstructed It is the feature about having a key corresponding to a node or a leaf as cryptographic key data. It carries out.
The side of The 12 of the present invention,
Category Lolli as subTree classified based on the category constitutes. It is carried out, From the route of Tree which constituted a plurality of devices as a leaf to a leaf Route on a path, It is a style about 1 Tree which matched 1 with the node and the leaf respectively. It accomplishes, Higher rank choose the path which constitutes the Keatuli 1 and according to the low rank key on a selection path A 1 Doki 1 Set corresponding to [ have encryption processed data of a key and ] the above-mentioned selection path It is a profit about A. It is the information recording medium which stored validation key block (EKB) whose decoding was enabled only in the device in which for is possible, and is '.
It decodes in each of subTree set up as partial A dragon 1 of the above-mentioned key Tree. 1 block of sub validation which can be processed (substitute EKB) Composition E KB is stored, this Synthesis corresponding to each substitute E KB contained in Formation E KB -- the data length of a sub E KB storing field -- Information storage intermediation having the composition which called and stored sub E K B identification data It is on the body.
it sets in the one embodiment of the information recording medium of the present invention -- the above-mentioned sub validation keeping Lock (substitute EKB) Each, They are an original algorithm and one original key' De evening respectively. Sub validation key block with merit (substitute EKB) It is Special about being constituted by carrying out. It is considered as the mark.
The side of The 13 of the present invention,
Path from the route of A tree 1 which constituted a plurality of devices as a leaf to a leaf Upper route, A 1 Do and Keatuli 1 which matched the key with the leaf respectively are constituted, Higher rank key choose the path which constitutes the key Tree and according to low rank 1 on a selection path It has encryption processed data, Node Keyset corresponding to the above-mentioned selection path Use of A is possible. are . Validation 1 Plock whose decoding was enabled only in the device (EKB) Debye It is an information processing method in a system with the composition with which A is provided,
The above-mentioned validation key block (EKB)
It decodes in each of Sabilli 1 set up as partial Tree of above-mentioned Keatuli 1. It is constituted as composition E KB of sub validation key block (substitute EKB) which can be processed, Each sub validation key block which stores the composition EKB (substitute EKB) Inner key Arrangement is held, and -- corresponding to each substitute E KB -- the data length of a sub E KB storing field -- as composition E KB with the composition which called and added sub E KB identification data -- a device -- Offer It is in the offering information processing method.
it sets in the one embodiment of the information processing method of the present invention -- above-mentioned Subtitled 1 -- power it is classified based on Age -- category managed by category and the entity It is Rili 1.
the above-mentioned sub validation key block (substitute EKB) Is the above-mentioned category' entity Match with the node or leaf belonging to category Tree which is set and self manages. , -- based on Killed 1, it is generated as EKB which can be processed -- in 1 issue center (K D C) it is based on substitute E KB whom the above-mentioned category' entity generated -- composition EKB as E KB usable in common is generated to a plurality of category Tree It is characterized by things.
it sets in the one embodiment of the information processing method of the present invention -- the above-mentioned sub validation keeping Lock (substitute EKB) An algorithm original with each and each, and original key . data Sub validation key block with merit (substitute EKB) As -- being constituted -- the feature It carries out.
Further, It sets in the one embodiment of an information processing method of the present invention, Above-mentioned Subtitled 1 is power. It is classified based on Age, Category category managed by 'entity It is Ritsuri 1. the above-mentioned sub validation keeping mouth Dug (sub E K B) Is The above-mentioned category. - A node or Li 1 who belongs to self Category Lolli to manage in an entity It can process based on a key matched with Off. It is generated as E KB, The above-mentioned composition. Each substitute in E KB The above-mentioned substitute stored corresponding to E KB Node which is an identifier of a node from which E KB identification data constitutes power Tego Lily They are the feature and To about it being I D. To.
it sets in the one embodiment of the information processing method of the present invention -- it is storing to the above-mentioned composition E KB 1 block of sub validation carried out (substitute EKB) Each, 1 Tree is constituted. They are a low rank node key or low rank Li 1 Japanese butterbur about the node key set up corresponding to each node. Encryption 1 data enciphered using 1, node of each above-mentioned cryptographic key data the existence of the node of the right-and-left position of the low rank of a position, or the cryptographic key data of a leaf position -- Show A To tag is included.
it sets in the one embodiment of the information processing method of the present invention -- it is storing to the above-mentioned composition E KB Sub validation key block carried out (substitute EKB) Each, Decoding of the substitute EKB is possible. Path which constitutes simplified Rie which used a Noh end node or leaf as the lowest stage It chooses and omits an unnecessary node. No of reconstruction hierarchy Tree reconstructed They are the feature and To about having a key corresponding to Do or a leaf as encryption 1 data. To.
The side of The 14 of the present invention,
Path from the route of A dragon 1 which constituted a plurality of devices as a leaf to a leaf Upper route, Keatuli 1 which matched the key with the node and the leaf respectively is constituted, Higher rank key choose the path which constitutes the key Tree and according to the low rank key on a selection path It has encryption processed data, Node tree 1 Set corresponding to the above-mentioned selection path Use of A is possible. are . Set to a device. 1 block of validation which accepted and whose decoding it enabled (EKB) Debye Validation key block (E K B) generation place in a system with the composition with which A is provided Reason -- computer - it is record about the computer . program made to run on a system it is the program recording medium carried out -- above-mentioned computer and program,
It decodes in each of Subtitled 1 set up as partial Tree of above-mentioned Keatuli 1. Selection step of 1 block of sub validation (substitute E K B) which can be processed,
The step which adds the data length and sub E K B identification data of a sub E K B storing field corresponding to each selection substitute E K B,
It is in the Have(ing) program recording medium.
it sets in the composition of the present invention -- Tree (Thurs.) Encryption key distribution composition of the configurational structure of structure using -- each apparatus -- each leaf of a n minute tree (leaf) the key distribution method of composition of having arranged is used -- passing a recording medium or a communication line For example, Co which is an encryption key of Content data Also Key The attestation key used for the Authentication processing to spread, or program code It has composition distributed with validation keeping mouth A.
a validation key block -- a cryptographic key data division and the position of a cryptographic key -- To indicate tag part The constitutes -- data volume -- few -- it carries out -- decoding processing in a device It makes it possible preparation and to perform quickly. By this composition, it is a just device. It becomes possible to distribute safely the data which can be decoded.
In one or more selected Category 1, it is an encryption key day which can be decoded. Validation key block (E K B) which is an evening block is generated, and it is to each category tree. While supposing at the device which belongs that it is usable in common, Processing is possible at which category Tree. Ability, i.e., the E K B type definition list in which it is shown whether decoding is possible, is used. The increase in efficiency of generation management processing of E K B is enabled.
the program recording medium of the present invention, for example, various program and codes, -- real -- as opposed to the general-purpose Computer evening' system in which a line is possible -- one Comb evening '-- a program -- Cong It is a medium provided in a form legible by the Pugh evening. Media are accounts, such as C D, F D, M O. Recording media or A net Transmission media, such as Network, etc. and especially the form of those are limited. There is nothing.
Pair predetermined in a such program recording-medium, and computer and system top It is computer - in order to realize the function of a U-Tap D gram. A program and record The collaboration relation on structure with a medium or a function is defined. if it puts in another way -- the -- passing a recording medium -- a computer' program -- computer '-- a system -- Ince by acting as Thor, a collaboration operation is demonstrated on computer and a system -- the same operation effect as other sides of the present invention can be obtained.
The system under explanation of the present invention is with the logical set composition of a plurality of devices. It does not restrict to what has There and each composition c device in the same case.
the object, the feature and advantage of further others of the present invention, and the example of the present invention mentioned below -- it attaches it becomes clear by detailed explanation rather than based on a drawing -- I will come out. Brief explanation of the drawings
Drawing 1, It is a figure explaining the example of composition of the information processing system of the present invention.
Drawing 2 -- in the information processing system of the present invention -- example of composition of an applicable recording and reproducing device It is a shown block diagram.
Drawing 3, To various 1 in the information processing system of the present invention, and encryption processing of data It is A dragon 1 lineblock diagram attached and explained.
Drawing 4 -- distribution of various 1 in the information processing system of the present invention, and data -- use -- It is a figure showing the example of 1 block of To be validation (EKB).
Drawing 5, Validation keeping mouth of Content key in the information processing system of the present invention It is a figure showing the example of distribution which uses A (EKB), and the example of decoding processing.
Drawing 6, Validation keeping Rodzuk in the information processing system of the present invention (EKB) It is a figure showing the example of Formatsuto.
Drawing 7, 1 block of validation in the information processing system of the present invention (EKB) It is a figure explaining the composition of a tag.
Drawing 8, It is a figure showing validation key block (EKB) and the contents key in an information processing system of the present invention, and the example of data composition which distributes Content collectively. Drawing 9, The example of processing in the device at the time of distributing validation key block (EKB) and Content key 1 in an information processing system of the present invention, and Content collectively is shown. It is a figure.
Drawing 1 0, validation key block in information processing system of the present invention (EKB) It is a figure explaining the correspondence at the time of storing contents in a recording medium. Drawing 1 It is a figure [ the conventional sending processing / processing / which sends 1, and validation key block (EKB) and Content key in an information processing system of the present invention ]. Drawing 1 In the information processing system of 2 and the present invention, it is an applicable common key encryption system. It is a figure showing a Authentication processing sequence.
Drawing 13 -- figure (1 of That ) showing the example of processing in a device with the data composition which distributes validation key block (EKB) and the attestation key in an information processing system of the present invention collectively it is .
Drawing 14 -- figure (2 of That ) showing the example of processing in a device with one De evening composition which distributes validation key block (EKB) and attestation 1 in an information processing system of the present invention collectively it is .
Drawing 1 In the information processing system of 5 and the present invention, it is an applicable public-key crypto system. It is a figure showing a Authentication processing sequence.
Drawing 1 6, attestation processing according [ on the information processing system of the present invention, and ] to public-key crypto system Place which uses and distributes validation key block (EKB) and Content key collectively It is a figure showing Reason.
Drawing 1 It is a figure showing 7 and the processing which distributes 1 block of validation (EKB), and encryption program data collectively in the information processing system of the present invention.
Drawing 1 In the information processing system of 8 and the present invention, they are applicable contents . An image It is a figure showing the example of M A C value generation used for generation of Glit check value (I CV), and is Ah. To.
Drawing 1 indicate the example of processing in a device to be the data composition which distributes 9, and validation key block (EKB) and the I CV generation key in an information processing system of the present invention collectively Figure (the 1) it is .
Drawing 20 -- the example of processing in a device is indicated to be one De evening composition which distributes validation key block (EKB) and the I CV generation key in an information processing system of the present invention collectively Figure (the 2) it is .
Drawing 2 In the information processing system of 1 and the present invention, it is applicable contents -. An image Anti-copying function at the time of storing Glit . Tsuzuk value (I CV) in media It is a figure to explain.
Drawing 2 In the information processing system of 2 and the present invention, it is applicable Content -. Int It is an opinion about the composition which manages Glit' Tsuzuk value (I C V) aside from a Content storing medium. It is a figure which carries out Ming.
Drawing 2 3, category classification of hierarchy Tree structure in information processing system of the present invention It is a figure explaining an example.
Drawing 2 It is a figure explaining 4 and the generation process of simplification validation key block in the information processing system of the present invention (E K B).
Drawing 2 It is a figure explaining 5 and the generation process of validation key block in the information processing system of the present invention (E K B).
Drawing 2 It is a figure explaining 6 and simplification validation key block (E K B) (Example 1) in the information processing system of the present invention.
Drawing 2 It is a figure explaining 7 and simplification validation keeping lock (E K B) (Example 2) in the information processing system of the present invention.
Drawing 2 Category Lolli of 8 and hierarchy Tree structure in information processing system of the present invention It is a figure explaining 1 management composition.
Drawing 2 Category Lolli of 9 and hierarchy A dragon 1 structure in information processing system of the present invention It is a figure explaining the details of 1 management composition.
Drawing 3 Category of 0 and hierarchy A dragon 1 structure in information processing system of the present invention It is a figure explaining 1 management composition.
Drawing 3 Category of 1 and hierarchy A dragon 1 structure in information processing system of the present invention It is a figure explaining Liza 1 Puno 1 Do in 1 management composition.
Drawing 3 Category Lolli of 2 and hierarchy Tree structure in information processing system of the present invention It is a figure explaining new Category 1 registration-processing Si 1 Can in 1 management composition, and is Ah. To.
Drawing 3 Category of 3 and hierarchy Tree structure in information processing system of the present invention -- It is To explain about the relation between new category Tree in management composition, and superordinate category Tree. It is a To figure.
Drawing 3 Category of 4 and hierarchy A dragon 1 structure in information processing system of the present invention It is a figure explaining substitute E K B who uses with 1 management composition.
Drawing 3 Category of 5 and hierarchy Tree structure in information processing system of the present invention It is a figure explaining Device Revoke processing with 1 management composition.
Drawing 3 Category of 6 and hierarchy tree structure in information processing system of the present invention It is a figure explaining the Device Revoke processing sequence in 1 management composition. Drawing 3 Category of 7 and hierarchy Tree structure in information processing system of the present invention It is a figure explaining updating substitute E K B at the time of Device Revoke in 1 management composition. Drawing 3 Category of 8 and hierarchy Tree structure in information processing system of the present invention It is a figure explaining Category 1 Revoke processing with 1 management composition.
Drawing 3 Category of 9 and hierarchy Tree structure in information processing system of the present invention It is a figure explaining the category Lily pork processing sequence in 1 management composition, and is Ah. To. '
Drawing 4 Category of 0 and hierarchy A dragon 1 structure in information processing system of the present invention It is an opinion about the relation between the Lipoku category tree in 1 management composition, and a superordinate category tree. It is a figure which carries out Ming.
Drawing 4 Category Lolli of 1 and hierarchy Tree structure in information processing system of the present invention It is a figure explaining a Key character setup with 1 management composition.
Drawing 4 Category Lolli of 2 and hierarchy Tree structure in information processing system of the present invention It is a figure explaining a Key character setup with 1 management composition.
Drawing 4 3 and key issue center in information processing system of the present invention (K D C) It is a figure explaining the Key character management table composition to manage.
Drawing 4 4 and key issue center in information processing system of the present invention (K D C) It is a E K B generation process flow figure based on the Key character management table to manage. Drawing 4 Ke at time of new Category Lolli 1 registration [ in / in 5 / the information processing system of the present invention ] It is a figure explaining the notice processing of IParity.
Drawing 4 It is To explain about the composition of 6 and the category tree in the information processing system of the present invention. It is a To figure.
Drawing 4 7, the E K B Request evening in information processing system of the present invention, and key issue S The relation between The and Tap level 'category' entity (T L C E), and example of processing It is a figure to explain.
Drawing 48, The E KB requester in the information processing system of the present invention, and key issue Center and example of hard structure of top-level 'category' entity (T L C E) It is a figure to explain.
Drawing 49, It is a figure explaining Deviceno which the device in the information processing system of the present invention holds - Do key (DNK).
Drawing 50, De 1 of the E KB type definition list in the information processing system of the present invention It is a figure explaining evening composition.
Drawing 5 1 and EKB type registration processing flow in information processing system of the present invention It is a shown figure.
Drawing 52, E KB type cancellation process flow in the information processing system of the present invention It is a shown figure.
Drawing 53 -- the A dragon 1 change-notice process flow in the information processing system of the present invention -- Show It is a To figure.
Drawing 54, E KB type list demand processing Off in the information processing system of the present invention It is a figure showing a low.
Drawing 55 -- substitute E KB generation processing in the information processing system of the present invention -- To explain It is a To figure.
Drawing 56 -- substitute EKB generation processing in the information processing system of the present invention -- To explain It is a To figure.
Drawing 57, It is a figure explaining the processing which generates EKB compounded from substitute EKB in the information processing system of the present invention.
Drawing 58, When there is a Revoke device in the information processing system of the present invention It is a figure explaining substitute E KB generation processing.
When there are 'figure 59 and a Revoke device in the information processing system of the present invention It is a figure explaining the processing which generates E KB compounded from substitute EKB.
Drawing 60, It is a figure explaining one De evening composition of E KB compounded from substitute E K B in the information processing system of the present invention.
Drawing 6 1, E KB compounded from substitute E KB in information processing system of the present invention It is a figure explaining one De evening composition.
Drawing 6 When there are 2 and Lipo 1 Device in information processing system of the present invention It is figure explaining one De evening composition of E K B compounded from substitute EK B.
Drawing 6 It can set to the one De evening distribution type system in the information processing system of 3 and the present invention. It is a figure explaining Revoke processing.
Drawing 6 It can set to the self-3 record type system in the information processing system of 4 and the present invention. It is a figure explaining Revoke processing. The best form for inventing
[System outline]
It is Show about the example of a Content distribution system which can apply the information processing system of the present invention to Drawing 1. To. Distribution side of Content 1 0 and Content receiving side 2 Various Cong Teng whom 0 has Contents or Content key is enciphered to the apparatus in which List reproduction is possible, and it is Sending. Trust is carried out. receiving side 2 Encryption Content received in the apparatus in 0, or dark item-ized Content key etc. are decoded and Content or Maintenance 1 is acquired -- reproduction of image data and voice data or execution of various programs is performed. distribution side of Content 1 0 and contents receiving side 2 The data exchange between 0, and A evening 1 The net, such as Network is passed -- or memory intermediation of D V D, C D, etc. which can be circulated It performs via the body.
Contents distribution side 1 As the data distribution means of 0, in Internet 1 1 and satellite Broadcast 1 2 and telephone line 1 Media 1, such as 3, D V D, and C D, there is the 4th grade -- on the other hand -- Cong Tengu receiving side 2 As the device of 0 personal computer (P C) 2 1 and the Pau evening pull device (P D) -- 2 2 and mobile phone, P Portable device 2 of D A (Personal Digital Assistants) etc. Record reproducers 2, such as 3, D V D, and a C D player 4, game terminal, etc. Vessel 2 only for reproduction There is the 5th grade. these Content receiving sides 2 Each device of 0, and conte Tennis distribution side 1 the contents provided from 0 -- A net means of communication, such as Network, -- or -- or media 3 It acquires from 0.
[Device composition]
Contents receiving side 2 shown in Drawing 2 in Drawing 1 As an example of the device of 0, it is record reproduction. Device 1 0 The composition Plock figure of 0 is shown. Recording and reproducing device 1 0 0, Input-and-output I/F (Interface) 1 20 and M P E G (Moving) Picture Experts Group Code 1 30, A/D, and D/A Converter 141 Input-and-output I/F (Interface) which it had 140 Code Processing means 1 50 and ROM (Read Only Memory) 1 60 and C P U (Central Processing Unit) 1 70 and memory 1 80 and recording medium 1 9 Five drives 1 It has 90, These Bus 1 1 It is mutually connected by 0.
input-and-output I / F-1 20, the picture supplied from the outside, a sound, a program, etc. -- several kinds -- the digital signal which constitutes contents is received -- bus 1 1 If it outputs on zero Bus 1 the digital signal on ten is received -- it outputs outside. MP E G Codec 1 30 and path 11 MPEG decoding of the data which is supplied via 0 and by which MP E G coding was carried out is carried out -- while outputting to input-and-output I/F140 MP E G encoding of the Dizzy evening Le signal supplied from input-and-output I / F-1 40 is carried out, and it is bus 1. 1 It comes out on zero. Power is carried out. Input-and-output I/F-140, AZD, and D/A converter 14 1 is built in. To. the analog signal as contents supplied from input-and-output I/F-140 and the outside is received -- AZD and D/A converter 141 -- (Analog Digital) AZD Convert It is To. as a digital signal -- MPEG Code 1 If it outputs to 30 Into MPEG Co 1 Deck 1 About the Dizzy evening Le signal from 30, they are A/D and a D/A party. -- Evening 1 By carrying out D/A (Digital Analog) conversion by 41, it outputs outside as an analog signal.
Scrambling means 1 5 It comprises 0 (Large Scale Integrated Curcuit), for example, 1-chip L S I, bus 1 1 Dizzy as contents supplied via 0 encryption of the Tal signal, decoding processing, or attestation processing is performed -- code data and decoding De one evening etc. -- bus 1 It has the composition outputted on ten. Scrambling means 1 Sov of not only 1 Tip L S I but various kinds [ 50 ] Style which combined To air or hardware Realizing by Formation is also possible. Sov As the processing means by To composition The latter part explains composition.
ROM 1 It is To store about one plog Ramde evening processed by 60 and the recording and reproducing device. To. CPU 17 0 is ROM 1. 60 and memory 1 It is a fruit about the program memorized by 80. It is carrying out a line and is MP E G codec 1. 30 and scrambling means 1 The 50th grade is controlled. Memory 18 It is 0, for example, nonvolatile memory, and is CPU 1. A program which 70 performs Mu and C P U 1 Required data and also a device perform on operation of 70. Keyset used for scrambling A is memorized. The latter part explains one set of . It carries out. Drive 1 Recording medium 1 which can record reproduce 90 and Digital de 1 Tha It is Drive about 95. By carrying out Motion, it is recording medium 1. They are read-out (reproducing) and bus 1 about 95 to digital data. 1 While outputting on zero, Bus 1 1 Digital de supplied via 0 -- About the evening, it is recording medium 1. It is made to supply and record on 95.
Recording medium 1 9 Optical discs, such as 5, for example, DVD, and CD, Digital de, such as semiconductor memory, such as a magneto-optical disc, a magnetic disk, magnetic tape, or RAM -- it is a medium which can memorize the evening -- this embodiment -- drive 1 9 as opposed to 0 -- attachment and detachment Suppose that it is possible composition. However, recording medium 1 9 5 and recording and reproducing device 10 It builds in 0. It is good also as composition to carry out.
scrambling means 1 shown in Drawing 2 5 as 0 and one one chip L S I -- composition Do is also good -- again -- Sov the composition which combined Toware and hard W -- real -- It is good also as composition which carries out present.
[About the tree (Thurs.) structure as key distribution composition]
contents distribution side shown in Drawing 1 1 [ next, ] Each Debye of 0 to Content receiving side 20 Possession style of the scrambling key in each device in the case of distributing code data to Ssu and data distribution composition -- a figure -- it explains using 3.
Casual flirtation 0*1 shown in the lowest stage of Drawing 3 5 is each device of Content receiving side 20. It is. namely, a figure -- hierarchy A tree 1 shown in 3 (Thurs.) each leaf (leaf : leaf) of structure -- it It is equivalent to the device of that.
each device 0~1 the time of 5, manufacture, or shipment -- or -- setting after that a figure -- hierarchy tree shown in 3 (Thurs.) it can set in structure -- from its own leaf to a route Key assigned to the node (node key) And it consists of a leaf key of each leaf. Key Set is stored in a memory. K 0 shown in the lowest stage of Drawing 3 000*K 1 1 1 1 Each device 0*1 It is the leaf key which swerved to 5, and was swerved and assigned to it, KR (roux crested ibis 1) of the highest rung from -- the lowest stage to 2nd paragraph (node) Indicated key : KR *kappa 1 1 Let 1 be a node key. Figure In A tree 1 composition shown in 3, device 0 is [ leaf key K 0000 and ] a node key. : K 000 and K 0 0, K 0, and KR are owned. Device 5K0 1 0 1 and K 01 0 and K 0 1, K 0, and KR are owned. Device 1 5 is K 1. 1 1 1, K i l l, K l l, K l, and KR are owned. in addition -- the tree of Drawing 3 -- a device -- 0~1 1 of 5 six pieces are indicated -- symmetry in which balance of four-step composition was also able to take A tree 1 structure Although shown as composition many Depice are constituted in A dragon 1 -- again -- A tree It is possible to have different number composition of stages in each part.
The device various type which uses DVD constituted enabling free attachment and detachment, CD, M D, a flash memory, etc. is contained in various recording media to each device contained in A dragon 1 structure of Drawing 3, for example, a device embedding type, and a device. Various application services can live together. such different De after vice and different application constitute [ coexistence ] -- a figure -- contents Yes shown in 3 The hierarchy Rie structure which is key distribution composition is applied.
In the system by which these various devices and application live together, it is an example. It is the same record intermediation about the portion enclosed with the dotted line of For example figure 3, i.e., device 0, 1, 2, and 3. It sets up as one group using the body. For example, group enclosed with this dotted line As opposed to the device contained inside, it collects -- enciphering common Content -- The Sending from Robaida Each Content key used [ device ] was sent. It is a contents fee from Ri or each device to a provider or a settlement-of-accounts organization etc. If it enciphers too and payment data is outputted, Processing will be performed when. A content provider or a settlement processing organization, and opportunity that performs data transmission and reception with each device Seki performs processing which bundles up the portion enclosed with the dotted line of Drawing 3, i.e., device 0, 1, 2, and 3 as One guru - A, and sends data. Multiple such groups exist in Tree of Drawing 3. a Content provider or settlement processing organization etc. -- the organization which performs data transmission and reception with each device, and message data distribution means It functions by carrying out. .
It generalizes by the node key, a leaf key, and the one existing key management Seng evening. Composition managed for every group by message data distribution means, such as pro Paida which may manage and performs various data transmission and reception to each group, and a settlement-of-accounts organization It may carry out. these node keys and a leaf key -- for example, cases, such as disclosure of a key, -- More new processing is performed -- this update process -- the key management Seng evening, a provider, a settlement-of-accounts organization, etc. -- real -- A line is carried out.
It is contained in like and one group [ that it is clear from Drawing 3 ] in this Tree structure. Device 0 of three To, 1, 2, and 3 hold 1K00 common as a node key, K 0, and KR. By using this node key share composition, it is community. It becomes possible to provide only device 0, 1, 2, and 3 with Maintenance 1. For example, node key held in common kappa 00 the very thing is used as a contents key, and it is setting To. He is Cong only with device 0, 1, 2, and common 3, without performing The and new key sending. A setup of ten Tsu key is possible. It is a node about new Maintenance 1K c 0 eta. 1 About value E n c (kappa 00, K c o n) enciphered by kappa 00, it is A net. Network is passed. It will be a device, if it stores in The or a recording medium and distributes to device 0, 1, 2, and 3.
0. Only 1, 2, and 3 solve code Enc (K 0 0, K c o n) using share Node tree 1K00 held in each device, and it is Content key. : It becomes possible to obtain K c o n. E nc (K a, Kb) is Ka about Kb. It is shown that it is the enciphered data.
it sets to t at a certain time -- key which device 3 owns: kappa omicron omicron iota iota and kappa omicron omicron iota,
kappa 0 0, kappa 0, and KR -- aggressor (Hawker) It having been analyzed and having exposed is revealed. a It was case -- it or subsequent ones and system (group of device 0, 1, 2, and 3) transmission and reception -- In order to protect one To be deleted evening, it is necessary to separate device 3 from a system. the -- a sake -- node key: K 00 1, kappa 00, K 0, and KR -- its new key of its kappa (t)
00 1 and K (t) 0 0 and K (*) omicron and kappa -- (t) it updates to R -- device 0, 1, and 2 -- That It is necessary to tell an updating key. It is here and is K. (t) a a a is a generation of key K a a a.
(Generation) : It is shown that it is an updating key of t.
distribution processing of an updating key -- it Explanation just. Renewal 4 of a key, for example, a figure, It is Show to (A). Block de 1 called Activation key block (E KB: Enabling Key Block) It is A net about the table constituted by the evening. Network, Or it is a rank to a recording medium. It performs by carrying out Payment and supplying device 0, 1, and 2. validation 1 block [ (EKB) ] -- a figure -- each leaf which constitutes Tree structure as shown in 3 -- an opposite -- encryption 1 for distributing the key newly updated by the device which carries out Response -- style It accomplishes. Validation key block (EKB) may be called renewal block of a key (KRB: Key Renewal Block).
Drawing 4 Must of renewal of node key to validation key block (EKB) shown in (A) It is constituted as Plock data with the data composition which can update only a Essential device. To. the example of Drawing 4 is set to device 0 in the Tree structure shown in Drawing 3, 1, and 2 -- one Plock de evening formed for the purpose of distributing generation's t updating node key -- is there. Device 0 and device 1 are so that clearly from Drawing 3, considering it as an updating node key The (t) 0 0 and K (t) 0 and K (t) R -- Being required, device 2, and updating A -- as Do key -- K (t) 0 0 1 and K (t) 0 0 and K (t) 0 and K (t) R is required. it is .
Drawing 4 As shown in EKB of (A), a plurality of cryptographic keys are contained in EKB. Encryption 1 of the lowest stage is E n c (K 0 0 1 0, K (t) 0 0 1). this Leaf key K 00 which device 2 has 1 Updating node key K enciphered by 0 (t) 00 it is 1 -- the leaf key which device 2 and self have -- this encryption decoding a key -- K (t) 0 0 1 can be obtained. K obtained by decoding (t) 00 using 1 -- Drawing 4 decoding of the 2nd step of cryptographic key E n c (K (t) 0 0 1, K (t) 0 0) is attained from under (A) -- updating Node tree 1K (t) Obtain 00. It can do. It is Drawing 4 one by one below. The 2nd step of cryptographic key E n c (K (t) 00, K (t) 0) is decoded from on (A), updating Node tree 1K (t) 0 and a figure -- 4 Decode cryptographic key E nc (K (t) 0, kappa (*) R) of one-step Huge from on (A). kappa -- (t) Obtain R. To. On the other hand, it is device K 00. 00. K 0 00 1 and node key K O O 0 are updated. The thing required as an updating node key which is not contained in an object is K. (t) 00 and K (t) 0 and K (t) It is R. Device 0 000. K 0 00 1, Drawing 4 (alpha) Top , -- decoding the 3rd step of cryptographic key E n c (K 000, K (t) 0 0) -- K (t) Acquire 00. Hereinafter, Drawing 4 The 2nd step of cryptographic key E n c (K (t) 00, K (t) 0) is decoded from on (A), Updating node key K (t) 0 and Drawing 4 From (A) to the 1st step Cryptographic key E nc (K (*) 0, kappa (t) R) is decoded, and it is K. (t) R is obtained. Thus, key K which device 0, 1, and 2 updated (t) R can be obtained. Drawing 4 The index of (A), the node key used as a decryption key, and Lee The actual address of Fukyu is shown.
Node key of the higher rank stage of A tree 1 structure shown in Drawing 3: K (t) 0 and kappa (*) Renewal of R Being unnecessary and node key K 0 When the update process of only 0 is required, Figure 4 By using 1 block of validation of (B) (EKB), it is updating node key K. (t) 0 0 can be distributed to device 0, 1, and 2.
Drawing 4 E KB shown in (B), for example, new Co shared in a specific group, It can use, when distributing Ntenki 1. as an example -- Drawing 3 -- a dotted line -- Show the recording medium with device 0 in a To group, 1, 2, and 3 is used -- new shelf A connoisseur's contents key K (t) Suppose that c o n is required. Data E n c which enciphered K co n which updated common A 1 Doki 1K00 of device 0, 1, 2, and 3 this time (t) 00 is used and a new shelf is. (K (t)) A connoisseur's updating contents key: K (t) kappa -- (t) c o n -- a figure -- 4 It distributes with E KB shown in (B). As one De evening which is not decoded in the apparatus of the group of Depice 4 etc. and others by this distribution Distribution becomes possible.
Namely, K obtained by device 0, 1, and 2 processing E KB (t) 00 is used. If the above-mentioned cryptogram is decoded, it will be contents key K in t time. (t) c o n is obtained. It becomes possible.
It is distribution] of Content key used about [E KB.
To Drawing 5, it is contents key K in t time. (t) As the example of processing which obtains c o n, K (t) using 00 -- new common contents key K (t) one De evening E n c (K (t) 00, K (t) c o n) and the figure which enciphered c o n -- 4 EKB shown in (B) -- recording medium It passes and processing of received device 0 is shown. That is, it is contents key K about Encryption Messe by EKB - Jitter. (t) It is the example set to c o n.
it is shown in Drawing 5 -- as -- generation stored in device 0 and the recording medium: Node tree 1K00 which E KB and the them at the t time store beforehand Mentioned above using 0. the same EKB processing -- node key K (t) 00 is generated. furthermore -- decoding Update Noki 1K (t) 0 using 0 -- updating Content keyK (t) c o n -- Recovery it calls -- leaf key K 0000 which he has in order to use it behind -- code It turns and stores.
[format of E K B]
Drawing 6 -- validation keeping mouth Dug [ (EKB) ] -- Formats The example of A is shown. Par Jon 6 0 1 is an identifier which shows the version of validation key block (EKB). Function which shows the correspondency of the function and contents which identify E KB of the newest [ version ] It has. A depth receives the device of the distribution place of validation keeping Rodzuk (EKB). The number of hierarchies of hierarchy A dragon 1 is shown. data pointer 6 it is a pointer in which the position of the data division in 03 and validation key block (E KB) is shown -- evening Gupoen evening 604 -- tag part A position and signature Poin evening 60 5 is the Poin evening which shows the position of a signature.
Data division 6 0 6 stores the data which enciphered the node key updated, for example. For example, it is To store about each cryptographic key about the updated node key as shown in Drawing 5. To.
Tag part 6 0 The enciphered node key which was stored in 7 and a data division, and leaf key It is a tag in which physical relationship is shown. the grant rule of this tag -- a figure -- it explains using 7. Drawing 7 -- as data -- previously -- a figure -- 4 The example which sends validation keeping lock (E KB) explained by (A) is shown. Boil the data at this time to be shown in front (b) of Drawing 7. To. It is contained in the cryptographic key at this time. It is Totsuno 1 door about the address of a Tap node. It is considered as a dress. In this case, updating key K of a route key (t) R is contained. A Tap node address serves as KR. data E n c (K (t) 0, K (t) R) of this time, for example, the highest rung, -- a figure -- position shown in hierarchy Tree shown in (a) of 7 It is. Here, the following data is E n c (K (t) 00, K (t) 0), and is in the position at the lower left of front data on Tree. The case where there is data, 0 and when there is nothing, 1 is set up for a tag. a tag -- as {a left (L) tag and a right (R) tag} -- a setup -- To be. There is data in the left of data E n c of the highest rung (K (t) 0, K (t) R). By that, since one De evening cannot be found in L tag = 0 and the right, it is set to R tag = 1. hereinafter -- a tag is set to all data -- Drawing 7 the data row shown in (c), and an evening A sequence -- composition -- To be.
A tag and data E n c (Kxxx, K y y y) are located where of a tree structure. It is set up in order to show whether it is. Key data stored in a data division It is a fault to E n c ... (Kxxx, K y y y) and the enumeration data of a key enciphered simply. A dragon 1 of the cryptographic key stored as one De evening with the tag which it came, and was mentioned above since there was nothing Distinction of the upper position is enabled. the Into which does not use the tag mentioned above -- a previous figure -- 4 -- opinion node and deck to which encryption data was made to correspond like composition of having revealed are used -- for example
0 : En c (K (t) 0 , K (t) r o o t)
00 : E n c (K (t) 00 , K (t) 0)
000 : E n c (K ((t) 0 00 , K (T) 0 0)
although it is also possible to have data composition like ... such an index if it has used composition, it will become redundant data and data volume will increase -- Network -- Through In the distribution etc. to carry out, it is not desirable. On the other hand, it is Show about a key position in the tag mentioned above. By using as Index data, distinction of 1 position is possible at small data volume. It becomes.
It returns to Drawing 6 and is E K B Formats. A is further explained. Signatures (Signature) are a key control center and contents, for example, it published validation key block (EKB). It is an electronic signature which Robaida, a settlement-of-accounts organization, etc. perform. Device which received EKB It is a just validation key block by signature verification. (EKB) Validation which the publisher published It checks that it is key block (EKB).
It is distribution] of Content key used and Content about [E KB.
The example which sends only a contents key with E KB in an above-mentioned example is explained. Although carried out, With the contents enciphered by the contents key, and Content key 1 cryptography key It is [ the enciphered contents key and ] a Encrypted Content Key encryption key by EKB. The composition sent collectively is explained below.
This data composition is shown in Drawing 8. Drawing 8 In the composition shown in (a), it is E n c (K c o n, c ont e nt) 8. 0 1, It is the data which enciphered contents (Content) by Content key 1 (K c o n), and Enc (KEK, K c o n) 802 is, It is the data which enciphered Maintenance 1 (K c o n) by contents key code 1 (K E K:Key Encryption Key), E n c (EKB, KEK) 8 03, Maintenance In one De evening which enciphered 1 cryptography key KEK by validation key block (EKB) A certain thing is shown.
here -- contents key cryptography key K E K, the node key (K 000 and K 0 0 ...) shown in Drawing 3, or a roux -- it may be crested ibis 1 (KR) itself -- the key enciphered by node key (K 00 0 and K 00 ...) or Le 1 crested ibis 1 (KR) again -- Ah An intermediary is also good.
Drawing 8 (b) and a plurality of contents are recorded on media -- E n c (EKB, KEK) 80 with its same it The example of composition in the case of using 5 is shown. Such a style Also in Formation, the data in which the link place linked to En c (EKB, KEK) is shown is added to each data, without adding the same E n c (EKB, KEK) as each data. It can have composition to carry out.
Node tree 1K0 which shows Content key cryptography key KE K in Drawing 9 in Drawing 3 0 is updated. Updating node key K carried out (t) 0 The example at the time of constituting as 0 is shown. In this case, in the group enclosed with the dotted line frame of Drawing 3, device 3 is disclosure of a key. Ribo -- The (exclusion) Noting that it is carried out, It is a figure (a) validation key block shown in 9 to the member of other groups, i.e., device 0, 1, and 2. (EKB) (b) Conte Check 1 (K c o n) Contents key cryptography key (kappaepsilonkappa = kappa (*) 0 0) Dark Item-ized data, (c) By distributing the data which enciphered contents (content) by contents key (K c o n), device 0, 1, and 2 are contents. It can obtain.
The decoding procedure [ in / in the right-hand side of Drawing 9 / device 0 ] is shown. Device 0 and leaf key K 0 which self holds from received validation keeping mouth A first It is business about 00. By the required decoding processing, it is a Content key cryptography key. (KEK = K (t) 00) Acquisition It carries out. next, K (t) 0 contents key K c o n is acquired by decoding by 0 -- contents are further decoded by Content key K c o n. These processings Use of Content of device 0 is attained. Also in device 1 and 2 By processing E K B in a respectively different processing procedure, it becomes possible to acquire a contents key cryptography key (K EK = K (t) 0 0), and is To use about contents similarly. To becomes possible.
Device 4 of other groups shown in Drawing 3, 5, 6 ... The leaf key which self holds also noting that this same data (EK B) is received, and a node key are used, and he is Cong. Ten Tsu key cryptography key (KEK = K (t) 00) is unacquirable. the same -- it also sets to Revoke(ed) device 3 -- the leaf key which self holds, and Node tree -- it comes out to acquire Maintenance 1 code 1 (KEK = K (t) 00) Only the device which has a crack and a just right decodes and uses contents. It becomes possible.
thus -- if delivery of Content key used is used for E KB -- the amount of one De evenings few -- it carries out -- and encryption Content whose decoding only the just right holder enabled safely -- Arrangement It becomes possible to carry out Trust.
It is although it is the composition which can be safely distributed via validation 1block (EKB), a contents key, encryption Content, etc. and a network, Validation keeping It is record intermediation of D VD, CD, etc. about lock (EKB), Content key, and encryption contents. It is also possible to store in the body and to provide for a user. in this case, a recording medium -- storing -- Decoding of Was done encryption Content Validation keeping mouth stored in the same recording medium It is composition To so that Content key obtained by decoding of Dug (EKB) may be used. The, Use only by the leaf key which only a just right holder holds beforehand, and a node key is possible. Distribution processing of Noh encryption contents, i.e., the user device which can be used, is limited. It was contents distribution becomes realizable with simple composition.
Drawing 1 The example of composition which stored validation key block (EKB) with encryption contents is shown in a recording medium 0. Drawing 1 Also in the example shown in 0, contents C 1* C 4 are stored in a recording medium, the data which matched corresponding-to each storing contents validation keeping mouth Dug (EKB) is stored -- further -- validation keeping of version M Lock (E KB -- M) is stored. for example, E KB -- it is used for 1 generating contents key K c o n 1 which enciphered Content C 1 -- for example, E KB -- It is use for 2 generating Content key 1 K c o n 2 which enciphered contents C 2. It is carried out. at this example, 1 block of Ba 1 John's M validation (EKB -- M) are records it is stored in the medium -- since contents C 3 and C 4 are matched with 1 block of validation (EKB -- M) To decoding of validation key block (EKB -- M) The contents key of Ri contents C 3 and C 4 is acquirable. E K B 1 E KB -- Since 2 is not stored in the disk, New providing means, for example, A net, It is each contents key by Network distribution or distribution by a recording medium. EKB required in order to decode -- 1, EKB -- It is necessary to acquire 2. Figure 1 E KB in case a contents key circulates among a plurality of devices is used for 1. The distribution of a contents key carried out and the comparative example of the conventional Content key distribution processing are shown. upper row (a) is formerly composition -- lower-berth (b) is an example using validation key block of the present invention (EK B). Drawing 1 In 1, it is Ka. It is Ka about (Kb) and Kb. It is shown that it is the enciphered data.
(a) as [ show / it is alike and ] -- a data transceiver person's justification is checked conventionally -- again -- one De evening in order to share session key K s e s used for encryption processing of transmission -- each Debye In between A On condition that attestation processing and key exchange processing (AKE : Authentication and Key Exchange) were performed and attestation was materialized, it is Content key at Session key 1K s e s. Processing which enciphers K c omicron eta and transmits was performed.
for example, a figure -- 1 1 In P C of (a) It enciphered by the received session key. Contents key K s e s (K c o n) is decoded by a session key, and K c o n is obtained. To is possible, It becomes possible to encipher acquired K c o n by save key K s t r which P C itself holds, and to save in an own memory.
Drawing 1 1 it sets to (a) -- content provider, Figure 1 1 Record Devi of (a) A 1 1 Also by the case where he would like to distribute in the form where data can be used only for 01, it P C and reproduces in between. When a device exists, Drawing 1 1 attestation processing is performed as shown in (a) -- its it processing in which a contents key is enciphered and distributed by Session key -- necessity It becomes. Also in P C and playback equipment which intervene in between, it generates in attestation processing, and is Both. Encryption Content key 1 is decoded by using a Noodle session key for having. It carries out and becomes acquirable about Content key.
-- A way and Drawing 1 1 Example using validation key block (EKB) shown in the lower berth of (b) It sets, As effective as a content provider to validation key block (EKB) Node key obtained by processing of 1 block of-izing (EKB), or a roux -- a crested ibis -- distributing data (the example of a figure K r o o t (K c o n)) which enciphered Maintenance 1 Kc o n by --, Apparatus smell which can process distributed E KB It enables only The to decode and acquire Maintenance 1K c o n.
therefore, a figure -- 1 1 Generate 1 block of validation (E KB) which can be used only for the right end of (b). the validation key block (EKB) and its EKB processing intermediary profit To be 1 Doki 1 or a roux -- sending collectively the data which enciphered Content key 1 K c o n by crested ibis 1, Processing of EKB is performed depending on Leaf key 1 which P C, reproduction apparatus, etc. which exist in between, and self have, and a node key. It cannot do. Therefore, the attestation processing between data transceiver devices and a session key Generation, Processing called encryption processing of contents key Kc o n by Session key 1 They are [ as opposed to / safely / a just device ] contents which can be used, without performing. It becomes possible to distribute a key.
P swerving the case where he would like to distribute the contents key which can be used also for C and a record reproducer -- That in Re, validation key block (EKB) which can be processed is generated -- distributing It becomes possible to acquire common Content key.
[Distribution of the attestation key which uses validation key block . (EKB) (common key system) To distribution of the data or the key which uses above-mentioned validation key block (EKB) ] It sets, Validation key block (EKB) and Cong Teng who are transmitted between devices Since Tsu or a contents key is maintaining the always same encryption form, data intermediary a roadway is stolen and recorded -- it transmits again later -- what is called a replay attack Ri and an illegal copy may be generated. this -- as To prevent and composition -- De overnight it sets between Sending devices -- performing the same attestation processing as usual, and key exchange processing It is an effective means. When this attestation processing and key exchange processing are performed here Above-mentioned validation key block (EKB) is used for attestation key K a k e to be used, and it is De. It distributes to vice, It has attestation 1 shared as a safe secret key, and explains the composition which performs attestation processing according to a common key system. That is, it is the example which used the encryption message data based on E KB as the attestation key.
Drawing 1 The mutual recognition method (IS0/IEC 9798-2) which used the common key encryption system for 2 is shown. Figure 1 Although D E S is used as a common key encryption system also in 2, it is a method of a common key encryptosystem. Other methods are possible if it is a formula. Drawing 1 it sets to 2 -- first -- B -- 64 Bit -- random -- several -- I D which Rb is generated and is Rb and self I D (b) is transmitted to A. this received A -- new -- 64 A bit generating random number R a of A -- R a, R b, and I D in order of (b), key K a b is used in the C B C mode of D E S, and one De evening is enciphered -- it is return to B It carries out. It is a record element of its that as key K a b and a secret key common to A and B. It is a key stored inside. D Encryption place with key K a b using the C B C mode of E S Reason, For example, in the processing using D E S, Exclusive OR of an initial value and R a is carried out, and it sets to a D E S encryption section, it enciphers using key K a b -- generating cryptogram E 1, carrying out exclusive OR of cryptogram E 1 and R b continuously, and setting to a D E S encryption section it enciphers using key K a b -- cryptogram E 2 are generated -- further -- cryptogram E 2 and I D (b) Carry out exclusive OR and set to a D E S encryption section. It enciphers and generates using key K a b. Ciphertext E 3 generate send data (Token-AB).
It is each account as a common secret key too about B which received this, and receiving data. Key K a b (attestation key) stored in Recording element It decrypts. method of decryption of receiving data a method -- cryptogram E 1 is first decrypted by attestation key K a b -- random number R a is obtained. next, cryptogram E 2 are decrypted by attestation key K a b -- exclusive OR of the result and E 1 is carried out, and R b is obtained. finally, cryptogram E 3 are decrypted by attestation key K a b -- carrying out exclusive OR of the result and E 2 -- I D (b) is obtained. like this -- R a and R bit I D which were produced by carrying out (b) obtains. Chi, R b, and I D (b) verifies whether it is in agreement with what B transmitted. This verification When it passes, B attests A as a just thing.
Next, B, which generates session key (K s e s) used after attestation (a random number is used for the method of generation method). and the order of R b, R a, and K s e s -- C B C A of D E S it enciphers using attestation key K a b by 1 Do -- A is returned.
A which received this, and receiving data are decrypted by attestation key K a b. Receiving data Since it is the same as that of a decoding method and decryption processing of B, details are omitted here. In R b and R a, A transmitted among R b, R a, and K s e s which were obtained in this way. It is verified whether it is in agreement with a thing. When it passes in this verification, A is considering B as a just thing. It attests. After attesting the partner of each other, it is after session key K s e s and attestation. It is used as a common key for secret communication.
When injustice and disagreement are found at the time of verification of receiving data, it is a mutual private seal. Processing is interrupted as that in which a proof failed. In above-mentioned attestation processing, A and B share common attestation key Kab. this -- using 1 block of above-mentioned validation (EKB) for common key K a b -- it is distribution to a device It carries out.
For example, Drawing 1 Validation for which either A or B can decode another side in the example of 2 To validation key block (EKB) which generated and generated key block (EKB) Intermediary attestation key Kab is enciphered, It is good also as composition which transmits to another side, being certain -- it is It is good also as composition which enciphers and distributes attestation key K a b by validation key block (EKB) which The 3 person generated validation key block (EK B) which both sides can use to DepiceA and B, and generated to devices A and B.
Drawing 1 3 and a figure -- attestation key K a k e common to the device of plurality [ 14 ] -- validation 1 The example of composition distributed by block (EKB) is shown. Drawing 1 Example to which 3 distributes attestation key K ak e which can be decoded to device 0, 1, 2, and 3, Drawing 14 is Ribo 1 The about device 3 in device 0, 1, 2, and 3. (exclusion) It carries out and receives device 0, 1, and 2. The example which accepts it and distributes the attestation key which can be decoded is shown.
Drawing 1 At the example of 3, it is updating Node tree 1K. (t) 0 By 0, it is attestation 1 Kake. Enciphered data (b), In device 0, 1, 2, and 3, it is each. The node key which it has, and node key K updated using the leaf key (t) It is Recovery about 00. The validation key block (EKB) in which an item is possible is generated and distributed. Each Debye A is Drawing 1. As shown in the right-hand side of 3, EKB is processed first. (decoding) It carries out, updated node key K (t) 00 is acquired -- next, acquired node key K (t) Attestation key enciphered using 00 : It is decoding about En c (K (t) 0 0, Kake). It becomes possible to carry out and to obtain attestation 1 K a k e.
Other devices 4, 5, 6, 7 -- 1 block of same validation (EKB) By the node key which self holds even if it receives, and a leaf key, EKB is processed and updated. Since node key K (t) 00 carried out are unacquirable, it is just De safely. An attestation key can be sent only to vice.
On the other hand, in the group enclosed with the dotted line frame of Drawing 3, as for the example of Drawing 14, device 3 is disclosure of a key. Lipoku (exclusion) Noting that it is carried out, Noodle of other groups Ba, i.e., device 0, 1, and 2 are only received, and it is validation key Props which can be decoded. It is the example which generated and distributed The (EKB). it is shown [ ] in Drawing 14 -- (a) validation keeping mouth A (EKB) The data which enciphered (b) attestation key (Kak e) by node key (K () 0 0) is distributed.
The decoding procedure is shown in the right-hand side of Drawing 14. device 0, 1, and 2 -- first -- Acceptance the leaf key or A 1 Do key which self holds from possessed validation keeping mouth A -- business By required decoding processing, updating node key (K (t) 00) is acquired. Next, K (t) Attestation key Kake is acquired by decoding by 00.
It updates using the leaf key which self holds, and a node key also noting that device [ of other groups shown in Drawing 3 ] 4, 5, and 6 -- and this same data (EK B) are received. Node key (K (t) 00) is unacquirable. it Revoke(ed) similarly Leaf key 1 which self holds also in device 3, and a node key -- updating A 1 Do key (K (t) 0 0) is unacquirable -- Depice which has a just right It becomes possible to decode and use an attestation key.
Thus, if the delivery using E KB of an attestation key is used, it will be few about data volume. Only as for a just right holder, it is safely [ carry out and ] good to distribute the attestation key whose decoding was enabled. It becomes ability.
[ distribution of the contents key which uses public key attestation and 1 block of validation (EKB)]
Next, contents key which uses public key attestation and validation key block (EKB) Distribution processing is explained. First, 1 which is a public-key crypto system 6 0 Biyori of A length About the mutual recognition method using a circle curvilinear code, it is Drawing 1. It explains using 5. a figure -- 1 it sets to 5 -- although E C C is used as a public-key crypto system, if it is the same public-key crypto system, it is A gap may be sufficient. Key size is also 1. 6 0 Bit It may not be A. Drawing 1 it sets to 5 -- first -- B -- 64 A bit random number Rb of A is generated -- it transmits to A. A which received this -- new -- 64 Bit Random number A k smaller than random number R a and prime number p of A is generated. That(ing) The and base point G -- Ak twice -- point Av= AkxG carried out is calculated -- generating electronic signature A. S i g to Ra, R b, and A v (X coordinates and Y coordinates) -- public key certificate of A Together -- B is returned. Here, R a and Rb are it 64 [ it ] Bit. A and X coordinates of Av upsilon coordinates are its it 1. 60 A bit Since it is A, it is sum total 448 Bit. The electronic signature to A is generated.
The public key certificate of A, Ra, Rb, Av, electronic signature :8 which received alpha.31, and Rb which A has transmitted verify whether it is in agreement with what B generated. as a result -- when in agreement, it is verification with the public key of a certificate authority about the electronic signature in the public key certificate of A it carries out -- the public key of A is taken out. And electronic signature A. S i g is verified using the taken-out public key of A.
Next, B and random number Bk smaller than prime number p are generated. and base point G -- Bk twice -- point B v = B k X G carried out is calculated -- electronic signature beta. S i g to Rb, Ra, and B v (X coordinates and Y coordinates) is generated -- A is returned with the public key certificate of B.
The public key certificate of B, and Rb; Ra, Av, and electronic signature B. S i g were received. Ra which alpha and B have transmitted verifies whether it is in agreement with what A generated. as a result -- when in agreement, it is verification with the public key of a certificate authority about the electronic signature in the public key certificate of B it carries out -- the public key of B is taken out. And electronic signature B .S i g is verified using the taken-out public key of B. A after succeeding in verification of an electronic signature is a private seal considering B as a just thing. It proves.
When both succeed in attestation, B is BkxAv (although Bk is a random number). Av is Ellipse. Since it is a point on a circle curve, multiplication-by-scalars calculation of the point on an elliptic curve calculates necessity, alpha calculates Ak XB V -- low rank 64 Bit of X coordinates of these points A -- session key (in the case which made the common key encryptosystem the common key encryptosystem of 64 Bit key length) used for communication after carrying out. of course, a Session key may be generated from Y coordinates -- it carries out -- 64 bits of low ranks it may not be . Send data is Cess if it sets to the secret communication after mutual recognition. It may not only be enciphered by Yonki, but an electronic signature may be attached.
When injustice and disagreement are found at the time of verification of an electronic signature, or verification of receiving data Processing is interrupted as that in which mutual recognition failed.
Drawing 1 Maintenance which uses public key attestation and validation key block (EKB) for 6 The example of distribution processing of 1 is shown. setting between P C with a Content provider first -- a figure -- 1 5 -- opinion Attestation processing by the revealed public key system is performed. A Content provider and Cong To Node tree 1 which the playback equipment which is a ten Tsu key distribution place, and a recording medium have, and a leaf key E KB which can therefore be decoded is generated, Co which performed encryption by an updating node key Key E (K c o n) and 1 block of validation (EKB) Private seal between P C It enciphers by Session key K s es generated in proof processing, and transmits to P C.
P C performs encryption by the renewal node key of [enciphered by the session key, and is Session about Content key E (Kc o n) and validation key block (EKB) ]. After decoding by Key, it transmits to playback equipment and a recording medium.
It is Executed content key E (K co n) about encryption according to the renewal node key of [by the node key or leaf key which playback equipment, a recording medium, and self hold, an owner -- Contents key Kc o n is acquired by decoding effect-ized 1 Prozek (E KB)].
It is Executed content key E (Kc o n) about [^item-ization [ according to this composition ] according to a [More new node key a content provider and on condition of attestation between P C, Validation Since keeping mouth Dug (E KB)] was transmitted, there was disclosure of a node key. The data transmission to a partner trustworthy also at a case becomes possible.
Although the example [distribution [ which uses 1 block of validation of a program code (EKB) ]] Mentioned above explained how to encipher and distribute a contents key, an attestation key, etc. using 1 block of validation (EKB), Effective in various program codes The composition distributed using-izing key block (EKB) is also possible. That is, it is the example which considered one encryption Message de evening by EKB as the program code. hereinafter -- this -- Composition is explained.
Drawing 1 They are 1 block of validation about a program code to 7. (EKB) For example, updating no The example which enciphers by Doki 1 and transmits between devices is shown. Depice 1 70 1 and Depice 1 7 Validation which can be decoded by the node key which 02 has, and a leaf key 1 block (EKB) Updating node contained in validation key block (EKB) It is device 1 about the program code which carried out scrambling by the key. It transmits to 702. device 1 70 2 processes received E KB and acquires an updating node key -- further acquiring decoding of a program code is performed by a Updated node key -- plog Ramco 1 Do is obtained.
Drawing 1 the example shown in 7 -- further -- device 1 7 Program acquired in 02 processing in a code is performed -- the result -- device 1 70 it returns to 1 -- device 1 70 1 is based on the result -- the example which continues processing further is shown.
To thus, the thing for which the program code which carried out scrambling by the updating node key contained in validation key block (EKB) and validation key block (EKB) is distributed Ri, in a specific device -- a decipherable program code -- the above-mentioned figure -- 3 showed It becomes possible to distribute to a specific device or a group.
[Composition which does correspondence of Tsuzuk value over transmitting Content (I CV:Integrity Check Value)]
in order [ next, ] to prevent the alteration of contents -- integrity Choi of contents a Dug value (I C V) is generated -- it matches with contents and calculation of I CV explains the processing composition which judges the existence of a Content alteration.
Integrity' check value of contents (I CV) (to for example, contents) It is calculated using the receiving hash function and is calculated by I CV = ha s h (K i ev, C I, C 2, ...). K i c V is I C V generation 1. C l and C 2 are the information on Content, and the message attestation numerals (M A C : Message authentication Code) of the critical information of contents are used.
D the example of MA C value generation using E S scrambling composition -- a figure -- 1 It is shown in 8. Drawing 1 In 8 composition It is motorcycle eight about the target Mezzage so that it may be shown. It divides per A, (Hereinafter, divided Message is set to Ml, mu 2, - - -, and munu), and which first carries out exclusive OR of initial value (Initial Value (hereafter referred to as I V)), and M 1 (the result is set to I 1). Next, I 1 is put into a D E S encryption section, and it is a key (hereafter referred to as K 1). used and enciphered (it comes out and sets power to E 1). continuously, exclusive OR of E 1 and M 2 is carried out -- (output E 2) which puts in the output I 2 to a D E S encryption section, and it enciphers using key 1. Hereinafter, this is wound. Encryption processing is performed to the message of return and all. EN which came out at the end is A me. It becomes sage attestation numerals (MAC (Message Authentication Code)).
A hash function is applied to the MAC value and I C V generation key of such contents. It uses and Integrity and check value of Content (I CV) are generated. Alteration I C V generated at the time of Content generation for example, it was guaranteed that there is nothing, new -- Co if I CV generated based on Tent is compared and the same I CV is obtained -- Cong if it is guaranteed that there is no alteration in Tengu and I CV differs -- an alteration -- Oh -- a judgment -- To be.
[The composition which distributes generation key K i c v of a Check value (I CV) by E KB], next the composition which sends K i c V which is a Integrity' check value (I CV) generation key of Content by validation 1 above-mentioned Plock are explained. That is, it is the example which made the encryption message data based on EKB integrity . check value (I C V) generation 1 of Content.
Drawing 1 9 and a figure -- the case where Content common to a plurality of devices is sent to 20 -- Integrity and Tsuzuk value student for verifying the existence of an alteration of the contents of Re and others The example of composition which distributes Formation key K i c V by validation keeping mouth Dug (EKB) is shown. Drawing 1 Example to which 9 distributes check value generation key K i c V which can be decoded to device 0, 1, 2, and 3, Figure 2 0 is Revoke about device 3 in device 0, 1, 2, and 3. (Elimination) The example which carries out and distributes Tsuzuk value generation key K i c V which can be decoded only to device 0, 1, and 2 is shown. '
Drawing 1 At the example of 9, it is updating A 1 Doki 1K. (t) 0 One De evening (b) which enciphered check value generation key K i cV by 0, In device 0, 1, 2, and 3 Each node key which it has, and node key K updated using the leaf key (t) 0 Validation key block (EKB) which can decode 0 is generated and distributed. respectively -- a device -- a figure -- 1 it is shown in the right-hand side of 9 -- as -- it is processing about E KB first (decoding) Carry out. By updated node key K (t) 00 is acquired -- next Acquired Node tree 1K (t) Check value generation key enciphered using 00 : It becomes possible to decode E n c (K (t) 0 0, K i c v), and to obtain check value generation key K i c v. By the node key which self holds even if other device 4, 5, 6, and 7 -- receives the same validation key block (EKB), and a leaf key, Node key K which processed EKB and was updated (t) Since 00 is unacquirable, it is just De safely. A Czech value generation key can be sent only to vice.
On the other hand, in the group enclosed with the dotted line frame of Drawing 3, as for the example of Drawing 20, device 3 is disclosure of a key. Revoke (exclusion) Noting that it is carried out, Noodle of other groups A , i.e., device 0, 1, and 2 are only received, and it is validation key A block which can be decoded. It is the example which generated and distributed The (E KB). it is shown [ ] in Drawing 20 -- (a) validation keeping mouth Dug (EKB) The data which enciphered (b) check value generation key (K i e v) by node key (K (t) 00) is distributed.
The decoding procedure is shown in the right-hand side of Drawing 20. device 0, 1, and 2 -- first -- Acceptance the leaf key or node key which self holds from possessed validation keeping mouth A -- business It is. By decoding processing, updating node key (K (t) 00) is acquired. Next, K (t) Check value generation key K i c V is acquired by decoding by 00.
It updates using the leaf key which self holds, and a node key also noting that device [ of other groups shown in Drawing 3 ] 4, 5, and 6 -- and this same data (EK B) are received. Node key (K (t) 00) is unacquirable. it Revoke(ed) similarly the leaf key which self holds also in device 3, and a node key -- updating no Do key (K (t) 0 0) is unacquirable -- device which has a just right It becomes possible to decode and use a check value generation key.
thus -- if the delivery using E KB of a check value generation key is used -- data quantity is lessened -- and check value generation whose decoding only the just right holder enabled safely It becomes possible to distribute 1.
Integrity' check value of such contents (I CV) is used. The illegal copy of E KB and encryption Content can be eliminated. metaphor The figure 2 as [ show / in 1 ] -- Content C 1 and Content C 2 -- each conte there are media 1 stored with 1 block of validation (EKB) which can acquire Key -- the case where this is copied to media 2 as it was is assumed. EKB and dark The copy of item-ized Content is about being possible and this at the device which can decode E K B. It can use.
Drawing 2 Correspond to the contents justly stored in each media as shown in (b) of 1. Composition and To which attach and store integrity' check value (I CV (C 1, C 2)) To. (I C V (C 1, C 2)), It is X to contents C 1 and contents C 2. Integrity ■ of the contents calculated using the number of Shea U I C V = h a s h (K i e v, C I, C 2) which is a Czech value is shown. Drawing 2 composition of (b) of 1 it sets -- Content 1 and Content 2 are justly stored in media 1 Cong Integrity . check value generated based on Tengu C 1 and Content C 2 (I C V (C I, C 2)) It is stored. Content 1 is justly stored in media 2 -- integrity' check generated based on contents C 1 A value (I C V (C 1)) is stored. It was stored in media 1 in this composition.
They are media 2 supposing it copies {EKB and contents 2} to media 2, This by which I CV (C 1, C 2) will be generated if a contents check value is newly generated It becomes, it differs from K i c V (C 1) stored in media -- contents storing of new Content by an alteration or an unjust copy was performed -- joy -- or -- it becomes. it sets to the device which reproduces media -- front step of a reproduction step Perform I CV Czech. coincidence of generation I CV and storing I CV is distinguished -- in agreement having composition which does not perform reproduction the case where there is nothing -- Content of an illegal copy It becomes possible to prevent reproduction.
Further, in order to improve safety, it is integrity 'of contents. Check As the composition generated based on the data which rewrote value (I CV) and includes a counter It is good. That is, it has composition calculated by I CV=ha s h (K i cv, c o unt e r+1, C 1, C 2, ...). Here, counter (c o unt e r+l) is set up as a value by which one increment is carried out for every rewriting of I CV. A counter value needs to have composition stored in a secure memory.
Integrity' check value of contents (I C V) Contents In composition unstorable in the same media, Integ of Content Composition which stores Lithi . check value (I C V) on media different from contents It may carry out.
For example, copy 1 preventive measures, such as MO of Medium Normal only for reading, should be taken. When it is and contents are stored in media, They are integrity and Choi to the same media. If Dug value (I CV) is stored, rewriting of I CV will be made by the inaccurate user. It is possible and there is a possibility that the safety of I CV cannot be maintained. In such a case, Hoss I CV is stored in the safe media on Thomassin, Copy Control 1 of contents It has composition which uses I C V for Le (for example, check-in/check-out, move). Safe management of Ri and I CV and the alteration check of Content are attained.
this example of composition -- a figure -- it is shown in 22. It reads in Drawing 22 and they are exclusive media, the usual MO, etc. Media 2 by which an anti-copying policy is not taken 2 0 Content is stored in 1, This Integrity and check value about the contents of Re and others (I C V) user Safe media 2 on the host machine with which accessing freely is not permitted 2 0 it stores in 2 -- unjust integrity' check value by a user (I C V) writes It is the example which prevented the substitute. As such composition, they are media 2. 2 0 It is Wear about 1. The devices worn and carried out are media 2. 2 0 P C which is a host machine when performing reproduction of 1, Composition and To which perform the check of I C V in a server, and judge reproductive propriety Reproduction of Leave, inaccurate copy Content, or alteration Content can be prevented.
[A category classification of hierarchy A tree 1 structure]
Let an encryption key be a hierarchy tree structure of Drawing 3, such as a route key, a node key, and a leaf key. Composed of is carried out, Style which enciphers and distributes Content key 1, an attestation key, a I C V generation key, or plog Ramco - Do, data, etc. with validation key block (E K B) Although Formation has been explained, It is each De about hierarchy A dragon 1 structure of defining the A 1 Doki first class. It classifies for every category of vice and they are an efficient key update process, cryptographic key distribution, and data. The composition which performs distribution is explained below.
Drawing 2 An example of the classification of the category of a hierarchy tree structure to 3 is shown. Drawing 2 in 3 -- story the highest rung of layer Tree structure -- route key K r o o t 2 3 0 1 is set up -- the following the middle stage -- node key 2 3 0 2 is set up -- the lowest stage -- Leaf key 1 -- 2 3 0 3 It is set up. Each device is From from a leaf key to each leaf key and a route key. The node key of A series and a route key are held.
Here, it is category node 2 about the node which has eye the The M stage from the highest rung as an example. 3 0 It sets up as 4. That is, it is a device of a specific category about each of the node of eye the The M stage. It is considered as a setting node. One node of the Mth step is made into the peak, and it is following and M+. The node and leaf about the device by which One or less step of A - Do and a leaf are contained in the category It carries out.
for example, a figure -- 2 One node 2 of eye the The M stage of 3 3 0 A category [memory State (trademark)] is set as 5. The node which stands in a row below in this node, and a leaf are memo Lister. It is considered as the node only for a category or leaf containing various devices which use A twig. Setting is carried out. Namely, node 2 3 0 It is a memo listee or less in five. Category of A A definition is given as the related node of Depice defined, and a set of a leaf.
It is subcategory node 2 about the low-ranking stage by several steps from M stage. 3 0 It is referred to as 6 and is To set up. To is made. For example, as shown in a figure, it is category [memo listee Dug] A 1 Do 2. 3 0 To the node under two steps of 5, it is a memo listee. In the category of Depice which uses A As the subcategory node contained, The node of [the vessel only for reproduction] is set up. Node 2 of the vessel only for reproduction which is subCategory no. 1 Do 3 0 Six or less Power of the vessel only for playback Node 2 of the telephone with a music regenerative function included in Age 3 0 7 is set up, That [P H S] node 2 contained in a low rank at the category of a telephone with a music regenerative function 3 0 8 and [mobile phone] node 2 3 0 9 can be set up.
Not only the kind of a category, a subcategory, and device For example, it is. The node which a maker, a content provider, a settlement-of-accounts organization, etc. manage uniquely, and That is A Processing unit, a jurisdiction unit or an offer service unit, and arbitrary units (these are [ total ] called and it is called the following and entity ) It is possible to set up. For example, one If it sets up as Peak A only for game machine machine X Y Z to which a game machine machine maker sells a category node - Do, It is the peak node to game machine machine X Y Z which a maker sells. Node key of the following lower berths, It becomes possible to store and sell a leaf key, and is distribution of after that and encryption contents, or distribution of various keys and an update process -- the top Validation keeping mouth constituted by an one or less point Node tree node key and the leaf key Dug (E K B) is generated and distributed -- as opposed to the device below a peak node -- use Distribution of possible data is attained.
Thus, following it makes one node into the peak and carries out it, it is the peak node about a node. The defined category or composition set up as a related node of a subcategory It carries out, It is a pipe about one peak node of the category stage or the subcategory stage. Validation 1 to which maker 1 who does Reason, a Content provider, etc. make the node the peak Prozek (E K B) is generated uniquely, It distributes to the device belonging to below a peak node. De belonging to the node of other categories by which the composition to carry out does not belong to a possible next door and peak node To execute' To can perform renewal of a key, without affecting vice at all.
[Key distribution composition (1) by simple E K B]
it explained previously -- for example, a figure -- it sets in the tree composition of 3 -- 1, for example, a contents key, Predetermined device (leaf) Case where it sends to addressing, The key distribution place device owns. Validation key block (EKB) which can be decoded is generated and provided using a To leaf key and a node key. for example, a figure -- 24 it sets in the Tree composition shown in (a) -- a leaf -- style setting to each node of a, g, and j, when transmitting key 1, for example, Maintenance, to device a, g, and j which carries out Formation -- it is generation about validation key block (EKB) which can be decoded It distributes by carrying out.
for example, updating route key K (t) r o o t -- contents key K (t) c o n -- dark it item-ization-processes -- the case where it distributes with EKB is considered. In this case, device a, g, and j each -- a figure -- 24 Use the leaf and node key which are shown in (b). performing processing of EKB -- K (t) r o o t is acquired -- acquired updating route key K (t) performing decoding processing of contents key K (*) c omicron eta by r o o t -- Cong Teng Luck 1 is obtained.
In this case, validation key block provided (epsilonkappabeta) Composition is shown in Drawing 25. It becomes like. Drawing 2 validation key block shown in 5 (epsilonkappabeta) a previous figure -- 6 explains Activation key block (epsilonkappabeta) Formats It is what was constituted according to A. There and data (cryptographic key) It has a corresponding tag. a tag -- previously -- a figure -- using 7 Explanation was carried out -- as -- the left (L) -- the right -- (-- if there is data in R) and the direction of its it -- 0 and non-if 1 is shown.
the device which received validation 1 Prozek (E KB) is based on the cryptographic key and tag of validation 1 Prozek (E KB) -- performing decoding processing of a cryptographic key one by one -- the upper -- about -- the updating key of the node is acquired. it is shown in Drawing 25 -- as -- a validation key block (EKB) and the number of stages from a route to a leaf (Debs), so that it is large -- the data Quantity increases. the number of stages (depth) Device (leaf) It increases according to a number. it is a thing -- the case where there are many devices used as the distribution place of a key -- data volume of EKB Increase size will be carried out further.
composition which enabled reduction of the data volume of such a validation key block (EKB) about -- it explains. Drawing 26, Validation key block (EKB) 1 distribution Devi It simplifies according to A and the constituted example is shown.
Drawing 25 -- being the same -- as opposed to device a, g, and j which constitutes a leaf -- key, for example, Co, The case where Ntenki 1 is transmitted is assumed. Drawing 2 as [ show / in (a) of 6 ] -- 1 Arrangement The tree constituted by only the Trust device is built. in this case, Drawing 24 being based on the composition shown in (b) -- as new Tree composition -- a figure -- 26 A dragon 1 composition of (b) is construction. It is carried out. if K j does not have branching from Kr o o t and only one branch exists -- Yo In order to result in Ka and Kg from To and Kr 0 o t, constitute a turning point in K 0. the figure of By force and dichotomy composition -- 26 The tree of (a) is built.
Drawing 26 Like and simplified Tree which have only K 0 as a node which are shown in (a) It is generated. validation key block [ (EKB) ] for updating key distribution -- these -- It generates based on simple A dragon 1. Drawing 2 6 A dragon 1 shown in (a), and validation keeping mouth The end node or leaf which can decode A (EKB) was used as the lowest stage. Dichotomized type List it is reconstructed by choosing the path which constitutes Lee and omitting an unnecessary node -- re--- It is construction hierarchy Tree. It is based only on the key corresponding to the node or leaf of validation key block for updating 1 distribution (EKB), and this reconstruction hierarchy A dragon 1, and is composition. It is carried out.
a previous figure -- although the data which enciphered the key of All until it results in validation key block (EKB) and K r oo t from each leaf a, g, and j which were explained by 25 was stored Encryption De 1 only about the node which constitutes Rie which simplified simplification E KB The evening is stored. Figure 2 6 A tag is 3 Bit as shown in (b). It has A composition. The 2 and The 3 Bit -- a figure -- having an example of 25, and the same meaning -- the left -- (-- L) -- the right -- (-- R) and it if there is data in the direction of it -- 0 -- 1 is shown if there is nothing. 1st Bit for A to show whether the cryptographic key is stored in EK B it is A -- data When are stored and there are not 1 and data, it is set up as 0.
It is stored in a network of data communication or a storage, and is a device. (leaf) It is provided. 1 block of Activation (EKB) Drawing 26 As shown in (b), it is shown in Drawing 25. As compared with composition, data volume will be reduced sharply. it is shown in Drawing 26 -- effective The 1 Bit of each device which received-izing key block (EKB), and a tag A -- 1 -- rank decoding only the data of the portion by which Payment was carried out one by one -- decoding of a predetermined cryptographic key It is realizable. For example, it is a leaf key about device a and encryption data E n c (Ka, K (*) 0). It decodes by kappa a, Node tree 1K (t) 0 is acquired and it is A. 1 Doki 1K (t) Encryption data E n c (K (t) 0, K (t) r o o t) is decoded by 0, and it is K. (t) r o o t is acquired. Depice j is a leaf key about one . encryption De evening E n c (K j, K (*) r o o t). It decodes by kappa j and is K. (t) ro o t is acquired.
Thus, simplified new A tree which is constituted by only the device of a distribution place One composition is built, Only the leaf which constitutes built Rie, and key of a node It uses and generates validation key block (EKB), Small data volume It is a possible next door and validation keeping mouth to generate 1 block of validation (EKB). Execution of data distribution of Dug (EKB) is attained efficiently.
[Key distribution composition (2) by simple EKB]
Drawing 2 validation keeping mouth Dug (EKB) generated based on simplified Tree which was shown by 6 is simplified further, and data volume is reduced -- efficient processing was enabled Composition is explained.
Drawing 2 The composition explained using 6 and validation key block (EKB) can be decoded. The end node or the leaf was used as the lowest stage. The path which constitutes dichotomized type Tree is chosen. It was a reconstruction hierarchy tree reconstructed by omitting a The unnecessary node. More Validation key block for new key distribution (EKB), and this reconstruction hierarchy tree It is constituted only based on the key corresponding to a node or a leaf.
Drawing 2 6 In the reconstruction hierarchy tree shown in (a), and leaf a, g, and j, it is an updating roux. Crested ibis 1K (t) It is Drawing 26 in order to make r o o t acquirable. Validation key block (EKB) shown in (b) is distributed. Drawing 2 6 it sets to processing of validation key block of (b) (EKB) -- leaf j -- one decoding of En c (K j, K (t) r o o t) processing -- route key : K (t) r o o t is acquirable. However, leaves a and g are E nc (Ka, K (t) 0). or decoding place of E n c (kg, K (t) 0) Reason -- K (t) performing decoding processing of E n c (K (t) 0 and K (t) r o o t) further, after obtaining 0 -- a roux -- crested ibis 1: K (t) r o o t is acquired. That is, it is necessary to perform leaves a and g and two decoding processings.
reconstruction hierarchy A dragon 1 which Drawing 26 simplified -- sable mentioned below when node K 0 is performing management original as a management node of the low rank leaves a and g As a A node When management of a low rank leaf is being performed, leaves a and g Although it is effective in the meaning which checks having acquired the updating key, node K 0 -- low rank Li 1 noting that it is carrying out when Off is not being managed or -- higher rank node , -- case where updating key distribution is permitted Drawing 26 reconstruction hierarchy A dragon shown in (a) 1 is further simplified -- 1 of node K0 may be omitted, and validation key block (EK B) may be generated and distributed.
The composition of 1 block of such validation (EKB) is shown in Drawing 27. Drawing 26 It is a key, for example, Content key, to being the same and device a, g, and j which constitutes a leaf. The case where 1 is transmitted is assumed. Like and the tree which connected each Re 1 Off a, g, and j with route Kr o o t directly which are shown in (a) of Drawing 27 is built.
Drawing 27 It is Drawing 26 as shown in (a). Simplified Rie by which node K 0 was excluded from reconstruction hierarchy A dragon 1 shown in (a) is generated. Validation for updating key distribution It generates based on 1block (E KB) and these simple Tree. Drawing 27 It is a route in A dragon 1 shown in (a), and the leaf which can decode validation key block (EKB). It is reconstruction hierarchy Tree reconstructed only with the path tied directly. Updating key Validation key block for distribution (EKB), and leaf of this reconstruction hierarchy tree It is constituted only based on a corresponding key.
Drawing 27 Although it is an example of (a), and the example of composition which used the end as the leaf, For example, the best It is top no also the case where a key is distributed to a grade node, or a plurality of middle rank and a low rank node. It is based on simplification A dragon 1 which connected Do, and middle rank and a low rank node directly, and is a validation keeping mouth. It is possible to generate Dug (EKB) and to perform key distribution. Thus, Tsu simplified with the peak node which constitutes reconstruction hierarchy A dragon 1 and the simplified tree It has the composition which connected directly the end node or leaf which constitutes Li 1. This Easy With an abbreviation-ized tree, branching from a peak node is not only 2 but a distribution node, or a leaf. It is possible to constitute as Tree which has three or more many branching according to a number.
a previous figure -- validation key block explained by 25 (EKB) The data which enciphered the key of All from each leaf a, g, and j to K r oo t is stored, and it is Drawing 2. Validation keeping Rodzuk explained by 6 (EKB) K 0 as a common node of the leaf key of leaf a, g, and j, a, and g -- further a roux -- it was the composition of having stored crested ibis 1 Drawing 27 1 block of validation based on simplification hierarchy Tree shown in (a) (EKB) Since the key of node K 0 was omitted, it is Drawing 27. Like and also day which are shown in (b) It becomes 1 block of little validation of the amount of evenings (EKB).
Drawing 27 validation keeping mouth Dug [ (EKB) ] of (b) -- a figure -- 2 6 Validation 1 of (b) That it is the same as that of block (EKB), and 3 Bit It has a tag of A composition. the 2nd and The 3 Bit -- a figure -- 2 6 explained -- the same -- the left (L:) -- the right -- (-- R) and the direction of its it -- data if it is -- 0 -- 1 is shown if there is nothing. 1st Bit the inside of A and EKB -- a cryptographic key -- rank Bit for whether Payment is carried out to be shown it is A -- when one De evening is stored, it is set up as 0 the case where there are not 1 and one De evening.
Drawing 27 it sets to 1 block of validation of (b) (EKB) -- each leaf a, g, and j -- (kg, K (t) r o o t) En c (Ka, K (t) r o o t) or E n c £]10 (1)<sub><</sub>'and 1^ (1) 0 0 It is a route key by one decoding processing of 1: : K (t) r o o t is acquirable.
The top node of reconstruction A dragon 1 simplified in this way, and at last Tree is constituted It is direct about an end node or a leaf, It is generated based on Tree with the connected composition. Activation key block (EKB) Drawing 2 7 Like and reconstruction hierarchy Tsu which are shown in (b) It is based only on the key corresponding to Lee's peak node and end node, or leaf. It is constituted.
Drawing 26 or figure Like [ of validation key block (EKB) explained by 27 ], Distribution The simplified new Tree composition which is constituted by only the previous device is built, Key of the leaf which constitutes built A dragon 1 or a leaf, and a common node Validation keeping Rodzuk (EKB) is generated using Body, Little data It is a possible next door and validation keeping to generate validation key block of quantity (EKB). Execution of data distribution of Rodzuk (EKB) is attained efficiently.
in addition -- as the subtree explained in the simplified hierarchy Tree composition and the latter part -- a setup -- In the E K B management composition of a To be category Tree unit, it is effectively utilizable especially. the node which constitutes A tree 1 composition as Category Lolli 1 and key distribution composition -- or -- It is a plurality of nodes or aggregate Prozek of a leaf chosen from the leaf. Kate They are Gorori 1 and the set set up according to the kind of device, Or De The executive unit of a vice-offer maker, a Content provider, a settlement-of-accounts organization, etc., etc. and a certain Both A processing unit with Point, a jurisdiction unit or an offer service unit, and various modes It is set up as a set. It classifies into one category Tree at a certain common category. The devices carried out have gathered, For example, peak node of a plurality of category Tree (The Bluto) The simplified same tree is reconstructed with having mentioned above, and it is raw about E K B. Formation is carried out, In the device belonging to selected category Tree, decoding is possible. Generation of simplified Noh validation key block (E K B) and distribution are attained. The latter part explains the management composition of one unit of power Tegogli in detail.
Such validation key block (E K B) and an optical disc, D V D, etc. It is possible to have composition stored in the information recording medium. For example, above-mentioned encryption Data division constituted with one data, In the hierarchy Tree structure of cryptographic key data It is further to validation keeping lock (E K B) containing the tag part as position identification data which can be set, Mezzage data of Content etc. which were enciphered by the updating node key The composition which provides each device with the stored information recording medium is possible. device the cryptographic key data contained in validation key block (E K B) -- discernment day of a tag part according to the evening, it extracts one by one and decodes -- acquiring a key required for decoding of contents It becomes possible to use Content. Of course, it is in Thane about validation keeping mouth A (E K B). Those, such as Tutu It is good also as composition distributed via Tact work.
[E K B management composition of one unit of Category]
Next, it is an opinion about the composition which manages the node or leaf which constitutes the tree composition as key distribution composition in Plock as a plurality of nodes or a set of a leaf. Ming is carried out. He is following Kate about the block as a plurality of nodes or a set of a leaf. It is called Gori lily. Category 1 and set set up according to the kind of device It is, or a device offer maker, a content provider, and a settlement-of-accounts organization etc. -- an executive unit, etc. a processing unit with a certain common appearance, a jurisdiction unit, or offer Service It is set up as a set of a A unit etc. and various modes.
About Category 1, it is Drawing 2. It explains using 8. Drawing 2 8 (a) is Tree. It is a figure explaining the management composition in one unit of Category. One Category 1 In a figure, it is example 2, for example, 1 category Tree, as a triangle. 7 0 In one, they are a plurality of A. - Do is contained. (b) shows the node composition in 1 category Tree. Two or more steps where one category Tree made one node the peak To dichotomized type Tree Intermediary composition is carried out. Hereinafter, peak node 27 of Category 1 They are a sub route and A call about 02. Fu.
end of a tree, it is shown in (c) -- as -- a leaf, i.e., a device, -- composition -- To be. let a device and two or more devices be leaves -- peak node 2 which is a sub route It belongs to one of Category 1 constituted by A dragon 1 with 702. Figure 28 It has like and Category 1 which are understood from (a), and a layered structure. this layered structure -- a figure -- it explains using 29.
Drawing 29 It is a figure for simplifying and explaining (a) and a layered structure, category Tree A 0 l~Ann is constituted from Kr o o t by the stage under several steps -- the low rank of category tree A l~An Category one B0 1*: B n k and also under [ its ] Category tree C 1* C nq is set to grade. each category tree -- Drawing 2 9 (b), as [ show / in (c) ] -- Tree constituted with two or more steps of nodes, and a leaf It has shape.
for example, composition of category Tree B nk, it is shown in (b) -- as -- sub route 28 1 let 1 be a peak node -- end node 28 1 It has two or more nodes until it results in 2. this category Tree has identifier B nk -- node in category Tree B nk Perform Node tree 1 corresponding management original with category Tree B nk, end node 28 1 Low rank set up considering 2 as the peak (child) management of category Tree -- real -- A line is carried out. On the other hand, they are Category Lolli Bnk and sub route 28. 1 It is end no about 1. Higher rank which it has as Do (parents) It is under management of category tree Ann.
the composition of Category 1 C n 3 is shown in (c) -- as -- sable 1 A 285 1 -- the top it is considered as a point node -- end node 2852 which is each device -- in this case -- a leaf -- From It has two or more nodes and a leaf to To. this Category 1 has identifier Cn3 -- the node key corresponding to the node in category tree C n 3, and a leaf, and leaf key pipe Perform Reason original with category Tree Cn 3, It is a pair to end node 2852. Leaf which carries out Response (Depice) Management is performed. On the other hand, they are category tree C n 3 and sub route 285. Higher rank which has 1 as an end node (parents) Category TreeB It is under management of n 2. The key management in each category tree is for example, renewal of a key. Although it is processing, Lipoku processing, etc., the latter part explains these in detail.
category to which a device belongs to the device which is a leaf of the lowest stage category Lee Sa which is a peak node of Category Lolli 1 of the leaf key of Littree to self which belongs The node key and leaf key of each node located in the path which results in bull 1 Tono 1 Do It is stored. For example, end node 2 8 5 Depice of 2, and end node (leaf) 2 8 5 Sub route node 2 from 2 8 5 Each key to 1 is stored.
Drawing 3 0 is used -- explain the composition of a category tree further. Category Tsu Lee can have the Tree structure constituted by the various numbers of stages. Under [ corresponding to the end node managed by the number of stages, i.e., depth (depth), and a category tree ] Grade (child) It sets up according to the number of category Tree, or the number of devices as a leaf. It is possible. .
Drawing 3 If up-and-down category Tree composition as shown in (a) of 0 is materialized (b) It becomes shown mode. It is Tree of the highest rung with Lou Torri 1 and a route key. Category 1A, B, and C are set to the end node of roux Tori 1 as a plurality of subordinate category trees, and he is Kate as low rank Category Lolli 1 of category Tree C further. Gori lily D is set up. Category Tree C 2 9 0 It is reserve node 2 about 1 and the node beyond '1 One of the end node. 9 5 It holds as 0, Self category to manage When making Ritsuri 1 increase, it has two or more steps of A tree 1 composition. Tegory LeeC and 2 9 0 It is reserve node 2 about 2. 9 5 0 is newly established as a peak node, management end node 2 9 7 0 is made to increase -- low rank Category Tsu which increased to the management end node Lee can be added.
Lizarupno 1 Do -- further -- a figure -- 3 It explains using 1. category TreeA and 3 0 it has 11, subordinate category TreeB and C to manage, and D-- one reserve Node 3 0 It has 21. A category tree is To et al. about subordinate category Tree for management. When you want to make it increase, reserve node 3 0 2 1 -- low rank Category of self-control 1A and 3 0 1 setting up 2 -- subordinate category TreeA and 3 0 1 End node of 2 , -- subordinate category trees F and G for management can be set up. self-control Low rank Category 1A and 3 0 1 2 -- the end A 1 Do -- few -- Both -- 1 -- Liza 1 Bunnode 302 Set up as 2, low rank Category 1A and 3 0 1 3 is set up -- management category Tree can be made to increase further Low rank Category tree A and 3 0 1 It is To secure about one or more reserve nodes also to the end node of 3. To. By taking such reserve node possession composition, it is a certain category tree. It becomes possible subordinate category Tree to manage and to make it increase boundlessly. Style set up only not only in one of reserve Category 1 and the end nodes It is good also as Formation. [ multiple ]
at Category 1 of its that, validation keeping mouth A (E KB) comprises one unit of Category Lolli -- 1 updating by one unit of Category and Revoke processing are performed It becomes things. Figure 3 In a plurality of category trees A and A and A", it is each category like 1. Although validation key block of Ritsuri 1 each (EKB) will be set up, this , -- category TreeA and A and A" are managed in common -- for example, a certain Device A car is able to manage collectively.
[Registration processing of new Category 1]
Next, the registration processing of new category Tree is explained. registration processing sequence a figure -- it is shown in 32. It explains according to the sequence of Drawing 32. new -- tree composition . -- it is added to inside -- new (child) Category Tree (N -- En) and higher rank (parents) Category An initial registration demand is performed to tree (P -- En). each Category 1 the public key according to a public-key crypto system is held -- public presentation of self [ tree / new category ] A key is sent to superordinate category tree (P -- En) on the occasion of a registration demand.
Superordinate category Tree which received the registration demand (P -- En) it received -- new (child) the public key of Category 1 (N -- E n) was transmitted to certificate issue office (C A : Certificate Authority), and the signature of C A was added -- new (child) the public key of category Tree (N -- E n) -- To receive' To. As new as these procedure and superordinate category tree (P -- E n) (child) It is carried out as a procedure of mutual recognition with category Tree (N -- E n). It is a higher rank after attestation of initial registration demand category Tree is completed by these processings. Category 1 (P -- En) new (child) Registration of category tree (N -- En) a permission is granted -- new (child) The node key of category tree (N--E n) is transmitted to new (child) power Age tree (N -- E n). This node key and superordinate category Tree (P -- En) It is one node key of an end node, and new (child) category It corresponds, peak A 1 Do, i.e., the sub route key, of Lily (N -- E n).
New, after this node key transmission is completed (child) Category Tree (N -- E n) it is new (child) A dragon 1 composition of category tree (N -- En) is built -- built tree the sub route key of a peak node received on the peak is set up -- of each node and a leaf 1 is set up and validation key block in category Tree (EKB) is generated. 1 block of validation in one category tree (EKB) are called substitute EKB. -- A way and superordinate category Tree (P -- E n) New (child) Substitute E K B in superordinate category tree (P1 E n) to which the end node which comes into effect was added by the addition of category Tree (N -- E n) is generated.
New (child) Category tree (N -- E n) New (child) Generation of substitute E KB constituted by the node key in category Tree (N -- En) and the leaf key will transmit this to superordinate category tree (P -- E n).
New (child) Higher rank category which received substitute E KB from category Tree (N -- E n) Lily (P -- En), Substitute EKB who received, and substitute E KB whom superordinate category Tree (P -- E n) updated are transmitted to a key issue center (KD C: Key Distribute Center).
It is Based to key issue center (KD C) and substitute E KB of all category Tree. It is and they are EKB of various modes, i.e., a specific category tree, and a device. It becomes possible to generate EKB which can decode Body. Thus, Kate who can decode He is for example, a Content provider about E K B which set up Gori tree or a device. It provides and a Content provider enciphers a contents key based on E KB, Network is passed -- or specific by storing in a recording medium and providing It becomes possible to provide the contents which can be used only by a device.
1 issue center of substitute E KB of a new category tree (KD C) is faced. Registration processing The is transmitted for substitute E KB one by one via higher rank Category Lolli 1, and it is To execute. It is an initial registration category, without passing not the thing to restrict to How to do but higher rank Category 1. Composition which performs processing directly registered into key issue center 1 (KD C) from a tree It may carry out. superordinate category Tree and low rank Category newly added to superordinate category Rie correspondence with 1 -- a figure -- it explains using 33. End node of higher rank Category 1 1 One 320 It is low rank Category considering 1 as a peak node of new addition category Tree. It is management of low rank Category 1 and superordinate category Tree by providing for Lee. It is added as a lower category tree. Category under management of a superordinate category tree Although the latter part explains a tree in detail, Revoke of a subordinate category tree (exclusion) The meaning that it is the composition that superordinate category Tree can Coast processing is included. it is shown in Drawing 33 -- as new Category 1 is set to superordinate category With Lee One node 32 of end A 1 Do which is a leaf of higher rank Category 1 0 As new as 1 Peak node 3 of Addition category Tree In 202, one end A . 1 Do which is one leaf of c, i.e., a higher rank node, set up as an equal node, New addition category It is set up as a sub route of Lily. New by being set up in this way Addition category Tree is validated under whole A dragon 1 composition.
When new addition category Tree is set to Drawing 34, higher rank Category 1 is Generate. The example of Update EKB is shown. Drawing 34, the composition shown in (a) -- namely, -- already -- effective -- existence the end node (n o d e 000) to carry out -- 3 30 1 and end node (no d e 0 0 1) 3 There is 302. It is new category Tree addition end A to a new addition category tree here. -- Do (no d e l O O) 3 30 When 3 is given, superordinate category Tree generates. Substitute's E KB example is shown.
Substitute E KB has the composition [ as ] shown in (b) of Drawing 34. It is Existence to the owner [ it / it ] effect. It is dark at the higher rank node key enciphered by the end node key which carries out In, and a higher rank node key. Item-ized further higher rank node key -- It goes on on a higher rank further, and is to a sub route key. It has the composition of resulting. Substitute EKB is generated by this composition. each Category Lee -- a figure -- 34 if shown in (b) -- the same -- effective end node, or leaf key the higher rank node key by which Encryption was carried out, and a higher rank node key -- further -- the node key of a higher rank -- dark it item-izes -- it has EKB constituted with the encryption data which carries out Fukashi thickness to a higher rank one by one, and results in a sub route -- this is managed.
[Revoke processing under Category 1 management]
Next, it can set in the composition which manages key distribution Tree composition as a category Tree unit. Lipoku of a device or category Tree (exclusion) Processing is explained. a previous figure -- that only a device specific out of the whole A dragon 1 composition at 3 and 4 can be decoded, and place which distributes validation key block (E K B) which the device which was carried out as for Lipo - The cannot decode Reason was explained. Drawing 3 From inside of Lipoku processing explained by 4, and whole tree Oh is a category of A dragon 1 by the processing which Revoke the device which is a specific leaf. In the composition by A dragon 1 management, execution of Revoke processing is attained for every Category. Drawing 3 Lipoku [ in / using five or less figure / A tree 1 composition under Category 1 management ] Processing is explained. Drawing 3 Category 1 which has managed Category Lolli 1 of lowest stage, i.e., each device, among category trees which constitute 5 and tree It is a figure explaining the Lipoku processing of a device to depend.
Drawing 3 5 The 1 distribution Tree structure by (a) and category tree management is shown. a route node is set to the Tree top -- the bottom of several of the steps -- category Tree A 0 1 *A n n -- further -- the low rank stage -- B 0 1*: category Tree of B n k -- further -- the -- lower -- about -- Category 1 of C 1* c n is constituted by the stage. Bottom Category 1 End node (leaf) Each device, for example, a record reproducer, vessel only for reproduction, etc. Suppose that it is.
Here, in Revoke processing and each category Tree, it performs uniquely. Metaphor At The and Category 1 C 1*C n of the lowest stage, it is Revoke processing of the Desbats . chair of a leaf. It performs. Drawing 3 5 category which is one of the category trees of the lowest stage at (b) Littree C n and 3 43 The Tree composition of 0 is shown. category tree C n and 3 4 3 0 and peak node 3 4 it has 31 -- device of plurality [ leaf / which is an end node ] It is the composition which it has.
The device which serves as a Revoke object into the leaf which is this end node, for example, Desbats, Chair 34 3 Supposing there is 2, it is category Tree C n and 3. 4 3 0, It updates uniquely. Validation constituted by the node key in category tree C n carried out, and the leaf key Key block (substitute E K B) is generated. This validation key block and Revoke Device 3 4 3 Depice smell which constitutes a crack and other leaves from decoding in 2 It is 1 Plock constituted by the cryptographic key which can decode only The. Category It generates as Lee's C n administrator, and substitute E K B who had this updated. Are concrete. Each node 34 which constitutes the path which stands in a row in Lipo 1 Device 3432 from a sub route 3 1, 3434, and the node key of 3435 are updated, Only in leaf devices other than Device [ Ribo - ] 3432, it is a cryptographic key which can be decoded about this updating node key. Carry out and let the constituted block be updating substitute E KB. the figure of this processing and the point -- 3 and 4 it sets in the Revoke processing composition set and explained -- a roux -- crested ibis 1 -- the top of a category tree It corresponds to processing replaced with the sub route key which is a point key.
thus, category tree C n and 3430 updated by Revoke processing -- an owner -- Effect-ized key block (substitute EKB) It is transmitted to a superordinate category tree. this place Synthesis and a superordinate category tree -- category tree B n k and 342 it is 0 -- Category Tsu Li 1 -- Cn and 343 Peak node 343 of 0 Category Tsu which has 1 as an end node He is Lee.
From category Tree B nk, 3420, subordinate category tree C n, and 3430 Validation key block (substitute EKB) If it receives, It is contained in 1 block of the . Category 1 C nk and 3430 peak A 1 Do 343 Category corresponding to 1 1B nk and 3 42 Zero end nodes 343 1, subordinate category Tree C n and 343 it sets to the key updated in 0 -- own category TreeB n.k and 342 The update process of substitute E K B of 0 is performed. Figure 3 5 It is Category 1B nk and 3 to (c). 42 A dragon 1 composition of 0 is shown. it sets to category tree B nk and 3420 -- updating pair Node tree 1 used as an elephant -- Drawing 35 Sub route 342 of (c) Revoke Debye from 1 End node 343 which constitutes Category 1 containing Snodoki on the path which results in 1 It is 1. Namely, node 3 of category Tree which has transmitted updating substitute EKB 43 Each node 342 which constitutes the path which stands in a row in 1 1, 3424, 3425 nodes A key serves as a candidate for updating. Node tree 1 of each of these nodes is updated and it is category Tree Bnk and 342. New updating substitute E KB of 0 is generated.
Validation key block which category tree B nk and 3420 updated (sub EKB) It is transmitted to superordinate category Tree. In this case, higher rank Category Lolli -- Category 1 -- Ann and 34 1 it is 0 -- category Tree B nk and 342 Peak node 342 of 0 It is category Tree which has 1 as an end node.
category Tree Ann and 341 0, subordinate category Tree B n k, and 3420 , -- validation key block (substitute EKB) If it receives It is contained in 1 block of the . To category tree B nk and 342 Zero peak nodes 342 Category Tsu corresponding to 1 Lee Ann and 341 Zero end nodes 342 1, subordinate category Tree B nk and 3 it sets to the key updated in 420 -- own category tree Ann and 34 1 The update process of substitute E KB of 0 is performed. Figure 3 5 It is category tree Ann and 34 to (d). 1 A dragon 1 composition of 0 is shown. category Tree An n and 341 it sets to 0 -- updating The target node key, Drawing 35 Sable 1 A 34 of (d) 1 Node 342 of category Tree which has transmitted updating substitute E K B from 1 Each A which constitutes the path which stands in a row in 1 - Do 341 They are 1, 3414, and a node key of 3415. No of each of these nodes Do key is updated and it is category tree An n and 34. 1 It is raw about new updating substitute E K B of 0. Formation is carried out.
performing these processings in category Tree of a higher rank one by one -- a figure -- 30 (b) It performs to explained route category Tree. By this the processing of a series of, it is a device. Revoke processing is completed. It is updated in each category Tree. It was substitute E KB Finally it is transmitted to key issue center (KD C), and is kept. It is a basis to updating substitutes EKB of key issue Seng evening 1 (KD C) and all the category tree. About and various EKB(s) are generated. With updating EKB and the Revoke(ed) device It becomes encryption keeping mouth A which cannot be decoded.
the sequence figure of Revoke processing of a device -- a figure -- it is shown in 36. a processing procedure -- a figure -- 3 6 It explains according to a sequence figure. First, device management in the lowest stage of A dragon 1 composition Category Tree (D -- En) Inside of device management category Tree (D -- En) They are a deed and device management about the renewal of a key required in order to eliminate the leaf for Revoke. New substitute EKB of category tree (D -- E n) (D) is generated. Updating substitute E KB It is sent to (D) and superordinate category Tree. Updating substitute E KB (D) is received. Higher rank carried out (parents) Category Tree (P 1 -- E n) Updating substitute E KB Renewal of (D) Updating substitute EKB (P 1) who updated the node key on the path which results in Updating and the sable from the end node of the end node key corresponding to a peak node - A is generated. these processings are performed in a superordinate category tree one by one -- substitute EKB of With who is finally updated and does is stored in key issue Seng evening 1 (KD C), and is managed. Figure Superordinate category Rie is a line about an update process by Revoke processing of a device to 37. It becomes and the example of validation key block (EKB) to generate is shown.
Drawing 3 7, it sets in the composition shown in (a) -- low rank Category containing a Revoke device It is a figure explaining the example of E K B generated in higher rank Category 1 which received updating substitute E K B from Lee. Peak A of the subordinate category tree containing a Revoke device - Do, and end node of superordinate category Tree (no d e l O O) 360 It is To correspond to 1. To.
From the sub route of a superordinate category tree and a superordinate category tree to an end node (n o d e lO O) 36 0 The node key which exists in the path to 1 is updated, and it is new updating. Substitute EKB is generated. Updating substitute EKB is Drawing 37. It becomes as shown in (b). updating -- a Was done key and an underline -- and -- gamma] is attached and it is shown. End A updated in this way Node tree 1 on the path from 1 Do to a sub route is updated, and it is the category Tree. It is considered as updating substitute E K B who can set.
(Next, the processing at the time of setting category Tree as the target which Revoke, i.e., category, Lipoku processing of Lily is explained.)
Drawing 38 The key distribution Rie structure by (a) and category Tree management is shown. a route node is set to the tree top -- the bottom of several of the steps -- category Tree A 0 1 *Ann -- further -- the low rank stage -- B 0 1*: category Tree of B n k -- further -- the -- lower -- about -- Category 1 of C 1* c n is constituted by the stage. Bottom Category Lolli 1 End node (leaf) Each device, for example, a record reproducer, vessel only for reproduction, etc. Suppose that it is.
Here, it is Revoke processing Category tree Cn and 373 Place performed to 0 Synthesis is explained. category tree Cn of the lowest stage, and 37 30 -- Drawing 38 it is shown in (b) -- as -- peak node 343 it has 1 -- Desbats of plurality [ leaf / which is end A 1 Do ] It is composition with a chair.
category Tree Cn and 3 73 Revoke(ing) 0 -- Category 1 -- C n and 3 When [ be / the package exclusion from the tree structure of all the devices belonging to 730 / possible ] To. category tree Cn and 3 73 Revoke processing of 0, category tree Cn, and 3 in category Tree B nk and 3720 which are superordinate category Rie of 730 -- real -- A line is carried out. Category tree B nk and 3 72 0 is category tree C n and 373. Zero peak nodes 373 It is a category tree which has 1 as an end node.
Category Lolli 1 B n k and 3720, Subordinate category tree C eta and 3 730 Li When a balk is performed, Category 1 -- Cnk and 3 Peak node 37 of 730 3 Category 1B nk corresponding to 1, and 3 End node 373 of 720 Update 1. The Revoke category tree 373 0 to category tree B n k, and 3 7 2 The node key on the path to the sub route of 0 is updated, and it is validation keeping mouth Dug. It generates and generates updating substitute E KB. The node key used as the candidate for updating is Drawing 38. Sub route 3 of (c) 72 End which constitutes the peak node of a Revoke category tree from 1 Node 37 3 It is Node tree 1 on the path which results in 1. Namely, node 372 1, 3724, and 3 725 and 37 3 The node key of 1 serves as a candidate for updating. Each of these nodes A node key is updated and it is category Tree B nk and 3. New updating substitute E K B of 720 is generated.
Or Category 1 B nk and 3720, Subordinate category Tree C n and 3 When Revoke of 730 is performed, Category tree Cnk and 3730 peak no Do 3 73 Category Tree B nk and 3720 end A 1 Do 373 corresponding to 1 1 does not update, The Revoke category Tree 3 730 to category tree B nk, and 3 End node 3 on the path to sable 1 A of 720 73 Renewal of the node key except 1 It may carry out, validation keeping mouth Dug may be generated, and updating substitute E KB may be generated.
Category 1 B nk and 3 72 Validation key block which 0 updated (sub EKB) It is transmitted to superordinate category Tree. in this case, higher rank Category Lolli 1 -- category Tree An n and 37 1 it is 0 -- category Tree: B nk and 372 Peak node 372 of 0 It is category Tree which has 1 as end A . 1 Do.
Category 1 -- Ann and 37 1 0, subordinate category Tree B n k and 3720 , -- validation key block (substitute EKB) If it receives being contained in the key block To category tree B nk and peak node 372 of 3720 Category Tsu corresponding to 1 Li 1 -- Ann and 3 7 1 End node 3 of 0 72 1, subordinate category tree B nk and 3 it sets to the key updated in 720 -- own Category 1 -- Ann and 3 7 1 The update process of substitute E K B of 0 is performed. Figure 38 It is a category tree to (d). An eta 37 1 The tree composition of 0 is shown. category tree Ann and 3 7 1 it sets to 0 -- node key used as the candidate for updating, Drawing 38 Sub route 37 of (d) 1 Node 3 of category Tree which has transmitted updating substitute EK B from 1 72 Each A which constitutes the path which stands in a row in 1 - Do 37 1 1 and 37 14 and 37 1 It is A 1 Do key of 5. each of these nodes -- no -- updating Do key -- Category 1 -- Ann and 3 7 1 new updating substitute E K B of 0 -- raw -- Formation is carried out.
performing these processings in category Tree of a higher rank one by one -- a figure -- 30 (b) It performs to explained route category Tree. By this the processing of a series of, it is a category. Revoke processing of a tree is completed. In each category tree, it is More. It is transmitted to substitute E KB and the last target in which new was carried out at 1 issue center 1 (KD C), and is kept. It is carried out. it is based on updating substitute E KB of 1 issue center 1 (KD C) and all category Tree -- various EKB(s) are generated. Updating EKB and Lipoku(ed) Kate It becomes encryption keeping mouth A in which decoding by the device belonging to Gorilly is impossible. the sequence figure of Revoke processing of Category 1 -- a figure -- 3 It is shown in 9. a processing procedure -- a figure -- it explains according to the sequence figure of 39. First, it is Revoke about category Tree. Category Tree management Category 1 to carry out (E -- E n) It is Must in order to eliminate end node' for [ in category tree management category tree (E -- E n) ] Revoke. A deed and category tree management category tree (E -- En) are new in the Essential renewal of a key. are . Substitute EKB (E) is generated. Updating substitute EKB (E), higher rank Category 1 It is sent. Updating substitute E KB Higher rank which received (E) (parents) Category tree (P 11 En) Updating substitute E KB End Node tree corresponding to the updating peak node of (E) It is More about the renewal of 1, and the node key on the path from the end node to a sub route. Updating substitute EKB (P 1) who did new is generated. these processings -- one by one -- superordinate category it performs in Tree -- substitute E KB of With who is finally updated and does -- key issue S It is stored and managed in the A evening - (KD C). key issue center (KD C) and way it is based on updating substitute E KB of category Tree of The -- various E KB is generated. Decoding by the device belonging to updating E KB and Revoke(ed) Category Lolli is impossible. are . It becomes encryption keeping mouth A.
Low rank Category 1 Lipoku(ed) by Drawing 40 and higher rank Kate who performed Lipoku The figure explaining correspondence of Gori lily is shown. End node 3 of a superordinate category tree 9 0 1, it is updated by Revoke of Category 1 -- Tree of superordinate category Tree End node 39 which can be set 0 Node key which exists in the path from 1 to a sub route New substitute E KB is generated by updating. As a result, Revoke(ed) low rank power Peak A 1 Do 3 of Tegori 1 9 Node tree 1 of 02, and end of higher rank Category 1 Node 3 9 0 The node key of 1 becomes inharmonious. It is after Revoke of category Tree. E K B generated by 1 issue center 1 (K D C), superordinate category Tree End node 3 set and updated 9 0 Will be generated based on the key of 1. so Device corresponding to the leaf of subordinate category Tree which does not hold the updating 1 To the decoding Ga impossibility of E K B generated by key issue center 1 (K D C) To.
Libor of the category tree of the lowest stage who manages a device in above-mentioned explanation Category Tree management Category which is in the middle of Tree although The processing was explained In the process as the above that the processing in which the superordinate category Lee Lee Lee is also the same An intermediary is possible. Entity management category Tree of the middle is Revoke(ed). All belonging to the low rank of Revoke(ed) category tree management category Tree Two or more category Tree and a device are put in block, and Revoke becomes possible.
Thus, by performing Revoke in a category Tree unit, it compares with the Revoke processing performed per device of one 1 One, and he is Libor in a simple process. The processing is attained.
[Key character management of category Tree]
next, it sets in key distribution A dragon 1 composition in a category tree unit -- each entity Key character (Capabi l ity) to permit is managed -- Co according to Key character The processing composition which performs Balance distribution is explained. It is Key character here. Or [ decoding of specific compression audio data is possible ], It is Pard about a specific voice reproduction method. Capacity's being carried out or a specific image processing program's being processed etc. and a device are When. It is the definition information on the data processing capacity of whether to be a device which can process Content [ like ] or a program, i.e., a device.
Drawing 4 The example of category Tree composition which defined Key character as 1 is shown. key distribution Tsu it resembles the maximum peak of Li 1 composition, and Le 1 Tonod is located -- category Tree of plurality [ lower layer ] -- Connection is carried out -- each node It is Tree composition with dichotomy. Here, it is Category Tsu. Lee 4 0 0 Key character in which 1 permits either of voice reproduction methods A, B, and C It defines as category Tree which it has. Are concrete, for example, a certain voice compression pro. It is category when music data compressed by gram 1A, B, or C method is distributed. Littree 4 0 0 The device belonging to category Tree constituted by one or less is compression De1. The processing which elongates Tha is possible.
It is category Tree 4 similarly. 0 0 2 is voice reproduction method B or C, Category tree 4 0 0 3 is voice reproduction method A or B and category Tree 4. 0 0 4 is voice reproduction method B and category tree 4. 0 0 Capability with possible 5 processing voice reproduction method C It defines as a category tree with Í.
on the other hand -- Category 1 -- 4 0 2 1, category which permits image restoration method p, q, and r It defines as Lily, Category tree 4 0 2 2 is an image restoration method of methods p and q, and category Tree 4. 0 2 Kate with Key character in which the image restoration of 3 of method p is possible It defines as Gori lily.
It is managed in such Key character information on each category Tree, and key issue Seng evening 1 (K D C). Key issue center (K D C), for example, a certain conte, They are various devices about the music data which Provider compressed by the specific compression program. When you would like to distribute, the device which can reproduce the specific compression program is received seeing -- 1 block of validation [ (E K B) ] which can be decoded -- capability of each category Tree Based on Í information, it is generable. Contents pro who provides Condensed Condensed 1 enciphered by validation keeping mouth A (E K B) generated based on Bayda and Key character information was distributed, and it enciphered by the contents key. Each device is provided with compression audio data. By this composition, processing of data is possible. are . When [ be / certainly providing a specific processing program only to a device / possible ] To.
Drawing 4 1 defines Key character information about all the category Tree. Although it is ing composition, Drawing 4 the composition of 1 -- like -- the category tree of All -- Kay Papi It is not necessarily required to define tee information. for example, a figure -- 4 it is shown in 2 -- as -- De Define Key character only about Category 1 of the lowest stage where vice belongs. Key character of the device belonging to category Tree of the lowest stage is managed in 1 issue Seng evening 1 (KD C), Possible Debye of the processing which a content provider desires Validation key block which can be decoded only to A (EKB) To category Tree of the lowest stage It is good also as composition generated based on the defined Key character information. Drawing 42 Category tree 4 in which the device was defined as the end node 1 0 1 = 41 0 5 -- Key character to kick is defined -- Kay Papi about the category tree of these It is the composition of managing a tee in 1 issue center (KD C). For example, category Tree 4 1 0 In 1, it is [ reproduction / voice ] method r about method B and image restoration. The device which can be processed belongs. category Tree 41 02 -- voice reproduction -- One If it is, the device which can process method q belongs about method A and image restoration. etc. -- it is .
Drawing 43 -- 1 -- Key character management Te which is set to issue center (KD C), and is managed -- the example of composition of a bull is shown. A Key character management table is Drawing 43. It is as it is shown in (a). It has data composition. Namely, Kate as an identifier who identifies each category tree Gori lily I D, Keypa which shows Key character defined as that category Lee Pity List and this Key character a list -- a figure -- 43 it is shown in (b) -- as Metaphor It will be [1] if Voice data reproduction processing method (A) can be processed, It cannot process, and if [0] and voice data reproduction processing method (B) can be processed, [1] and processing are impossible for that. That is [0]. It is 1 Bit about the propriety about data processing of -- etc. and various modes. Every [ A ] [1] or [0] is set up, and it is constituted. Setup of this Key character information Cay about the management device of not only a form such [ a method ] but Category 1 Other composition may be used as long as it is identifiable in a papillae tee.
When stored in Key character management Te 1 bull at one De evening base where substitute E KB of each category tree or substitute E KB is another, substitute E KB discernment information is stored -- further -- sub route node identification data of each category Tree It is stored.
It is based on key issue Seng evening 1 (KD C) and a Key character management table, and is an example. Validation keeping mouth List which can decode only the device which can reproduce the contents of For example specification The (EKB) is generated. Drawing 44 -- using -- validation based on capability information Generation processing of keeping mouth A is explained.
step S 430 [ first, ] it sets to 1 -- key issue center 1 (KD C) and Keypa Category Tree with Key character specified from the Purity management table It chooses. When you would like to distribute that it is concrete, for example, there is renewable data based on voice data reproduction processing method A in a content provider, Drawing 43 Capability of (a) The item of voice data reproduction processing from List (method A) for example, is set as [1]. Category Lolli 1 is chosen.
next, it sets to step S 4302 -- selected Category Lolli 1 -- composition Squirrel of selection category Tree I D carried out A is generated. Next, step S 43 0 Path required for the tree which comprises 3 with selection category tree I D (path of key distribution Tree composition) It chooses. step S 4304 -- selection Category 1 -- it is judged whether all the path selections included in the list of I D were completed -- Up to complete A path is generated in step S 4303. This and a plurality of Category When 1 is chosen, the processing which chooses each path one by one is meant. Selection category When all the path selections included in the list of Tree I D are completed, it is Step S 430. It is [ progress, the selected path, and ] a style only by selection category Tree to 5. The key distribution Tree structure to accomplish is built.
step S 430 [ next, ] it sets to 6 -- step S 430 Tree style generated by 5 the update process of the node key of Construction is performed -- updating Node tree 1 is generated. substitute E K B of the selection category tree which constitutes A dragon - Key character management table , -- extraction -- substitute EKB, Step S 43 0 To the updating node key generated by 6 It is [ in / it is based and / the device of a selection category tree ] a validation keeping mouth which can be decoded. Dug (EKB) is generated. Thus, only in a device with generated validation key block (EK B) and specific Key character, it is use, i.e., decoding. It becomes possible validation key block (EKB). Content key 1 is enciphered by this validation key block (EKB) -- that Content key -- specific program It is based, encipher compressed contents and provide for a device, Key issue Only in the device with selected center (KD C) in which specific processing is possible Content is used.
Thus, it is a basis to key issue center (KD C) and a Key character management table. Validation which can decode About, for example, Depice which can reproduce specific contents, 1 Prozek (EKB) is generated. Therefore, a new category tree is registered. In a To case, the capability of the initial registration category Tree is acquired beforehand. It is needed. the notice processing of Key character accompanying this category Tree initial registration -- One it is -- a figure -- it explains using 45.
Drawing 45, Keypa in case new category Tree participates in key distribution Tree composition It is a figure showing the notice processing sequence of Purity.
it is newly added during tree composition -- new (child) Category tree (N -- En) and higher rank (parents) An initial registration demand is performed to category Tree (P -- E n). the public key according to each Category 1 and a public-key crypto system is held -- new Category Tsu Li 1 faces a self public key a registration demand -- it is sending to superordinate category Tree (P -- En) It carries out.
Superordinate category tree which received the registration demand (P -- E n) it received -- new (child) the public key of category Tree (N -- E n) was transmitted to certificate issue office (C A : Certificate Authority), and the signature of C A was added -- new (child) The public key of Category 1 (N -- E n) is received. As new as these procedure and higher rank Category 1 (P -- E n) (child) It is carried out as a procedure of mutual recognition with category tree (N -- E n). It is a higher rank after attestation of an initial registration demand category tree is completed by these processings. Category 1 (P -- En) new (child) Registration of category Tree (N -- En) a permission is granted -- new (child) The node key of Category 1 (N -- E n) is transmitted to new (child) power Tegory Lee (N -- E n). It is this node key and one node key of the end node of higher rank Category 1 (P -- En), and new (child) category It corresponds, the peak node, i.e., the sub route key, of Littree (N -- E n).
New, after this node key transmission is completed (child) Category Tree (N -- E n) it is new (child) the Tree composition of category Tree (N -- E n) is built -- built tree the sub route key of a peak node received on the peak is set up -- of each node and a leaf -- setting up -- Validation key block in category Tree (substitute EKB) Generate. On the other hand, it is a superordinate category tree. Also (P -- E n) New (child) Substitute E KB in the superordinate category tree (P1 E n) to which the end node which comes into effect was added by addition of category tree (N -- E n) is generated.
New (child) Category 1 (N -- E n) New (child) If substitute EKB constituted by the node key in category Tree (N -- En) and the leaf key is generated, this is transmitted to superordinate category tree (P -- En) -- further -- self Category Lolli the Key character information about the device managed by 1 -- superordinate category Tree -- connoisseur Knowledge is carried out.
New (child) Substitute EKB from category tree (N -- E n), and Key character Superordinate category Tree which received information (P -- En) Substitute E KB who received, and Key performance information and substitute EKB that superordinate category Tree (P -- En) updated It transmits to key issue center (KD C:Key Distribute Center).
substitute EKB of key issue center (KD C) and the received category tree -- and -- Key character information -- a figure -- it registers with the Key character management table explained by 43 -- a Key character management table is updated. key issue center (KD C) and updating it is based on the Key character management table carried out -- EKB of various modes, i.e., Special, It enables only Category 1 or a device with Key character of a law to generate E KB in which a back item is possible.
[E KB management composition which uses a E KB type definition list]
Next, E KB which can be decoded is generated in one or more selected category trees. Composition which provides the device belonging to a In each category tree with E K B usable in common It sets, The composition which uses the processing possibility of, i.e., the E KB type definition list in which it is shown whether decoding is possible, by which Category 1 is explained.
If it sets in this composition, it is a key issue center. (KD C) Content provider E KB issue requesting is received from the E KB Request evening which desires use of which EKB, and issue processing. It carries out. E E KB type defined as KB issue requesting by the E KB type definition list shown E KB type discernment casual flirtation 1 is included -- key issue center (KD C) According to an EK B type discernment number, it processes in 1 or a plurality of Category 1. (Recovery item) Possible EKB is generated. If generation of EKB is faced, it is 1 issue Seng evening 1. (KD C) EKB type definition Squirrel A of each Category 1 set up corresponding to the E KB type discernment number of A It is based on a P-node identifier, Tap level Kate as Category 1 administrator Gori' entity [ (T L C E : Top Level Category Entity) ] -- substitute EKB -- raw -- Require Formation. every -- substitute EKB whom T L CE generated is received -- a plurality of substitutes' EKB Synthesis process is performed and EKB which can be processed is generated in a plurality of Category 1. If it sets in this composition, he is an issue requesting person of EKB of content provider (CP) etc. E KB type definition squirrel Selection of specific Category Lolli is performed based on A. Things become possible. In a specific category tree, the issue requesting person of E KB, such as a content provider (CP), requests from key issue center (KD C) issue of E K B which can be processed with reference to a E K B type definition list. Key issue center 1 (KD C) is based on E KB issue requesting, Management entity of selected category Tree Management An event of Category 1 each chosen by receiving and making sub E K B issue requesting Tee tee, In the just device by which management Entity is not Lipoku(ed) It is accepted, substitute EKB who can process is generated and it transmits to a key issue center (KD C). Key issue center (KD C) combines one or more substitutes E K B, and is Depart of E K B. E KB which can be processed only to selection category Tree which the line demand person demanded is generated, and it provides for a E K B issue requesting person. EKB issue requesting person and key issue center 1 (KD C) , -- code which can be decoded only by the key which can receive EKB and can acquire E KB by processing Distribution of a-izing key or encryption contents is performed.
First, the composition entity in the following explanation is explained briefly.
Key issue center (KD C : Key Distribution Center)
validation block (EKB) is published -- EKB tie about published EKB A definition squirrel A is managed.
Top-level 'category' entity (T L CE: Top Level Category Entity) Entity which manages a certain Category Lolli. For example, Fau of record Deputy Mat Holder 1. category Tree is managed -- Debye in category Tree under management in A -- processing (decoding) substitute E KB who is possible E KB is generated -- key issue Seng Evening 1 (KD C) is presented. E KB and the Request evening (EKB requester)
For example, electronic contents offer (E CD : Electronic Content Distribution) Content provider (CP) etc. which perform service, A picture, a sound, and Prodara Entity which provides various contents, such as Beam, to a user device, being certain -- it is -- Formats of an archive medium it is A holder -- cryptographic key of offer contents etc. -- as a setup using a key acquirable by E KB processing -- Content and Media is provided. In this case, the issue requesting of E KB to be used is required from a key issue center (KD C).
for example, Content provider (CP) and a key issue center -- raw -- Encipher one's Content using route key of accomplished EKB (Root Key). It distributes. [ (KD C) ] Formats of an archive medium A holder is Made of an archive medium about E K B. It writes in and distributes at the time of Construction, and Content recorded is enciphered using Le 1 Toky (Root Key) of the E KB.
(A dragon 1 management of TL CE and a category base)
Although mentioned above about Tree management of the category base, Drawing 46 is used about the relation between top-level 'category Li - Enti' tee (T L C E) and Category 1. Explanation is carried out.
first, it is a set of a category and the device which had the same character as mentioned above -- the same concrete maker device or the same encoding Formats It is a device etc. which can treat A. In Drawing 46, A, B, C, and D are its category of its. Ritsuri 1 is shown.
Drawing 46 -- setting -- it is, roux Tori (the number of node stages) 1 , for example, the eight-step composition, of the highest rung, and the top node of category Tree is set to Le 1 Torri's 1 lowest stage. power Tegori 1 and plurality are able to become a relation of a higher rank and a low rank -- Drawing 46 -- it is -- it corresponds to category tree C and the higher rank of category Tree D.
category Tree which stands in a row directly in route Tree of the highest rung -- Top level category it is called Lee -- the entity which manages top-level Category Lolli -- Tobe Plebe It is called Le 'category' entity (TL CE). Drawing 46 -- A, B, and C -- A it is a Strange bell category -- the entity which manages these -- a top level and power It is Age' entity (TL CE). Top-level 'category' Enti There are tee (TL CE) and responsibility of managing below whole Tree of self fundamentally. That is, it is One to A dragon 1D like T LC E which manages tree C of Drawing 46, and A dragon 1C. Management to require is also performed. if Category Lolli of further a lower layer exists below in D -- the -- Lower layer category tree management is also performed. However, it is a pipe, for example about lower layer category tree D. The power Age entity (Sub Category Entity) which carries out Reason is placed, and it is the responsibility and right. Transferring is also possible.
each device, such as a recording and reproducing device using Content, and top-level category' entity [ (TL CE) ] -- the leaf of a certain Tree -- assignment -- The key of some nodes between the paths from the leaf to Re and a route is owned. The group of the node key which one device has is called device . node . 1 (DNK : Device Node Key). How many keys does each device have? (how many keys are included at DNK?) Tap level - Category entity (TL CE) is determined. It is a key issue center to Drawing 47. (KD C) Correspondence of top-level . category , entity (TL CE) EKB, and requester each entity and the outline of processing are explained. A figure is shown.
Key issue Seng evening 1 (KD C) 45 1 1, EKB distribution Sis using A dragon 1 composition Tem's management entity 45 1 It is positioned as 0. Management entity 45 1 Certificate authority (CA) which performs signature processing of as opposed to EKB in 0 further 45 1 There is 2.
Key issue Seng evening 1 (KD C) 45 1 1, top-level category Tree, etc. E KB type definition squirrel which mentions key management of Subtitled 1 below by carrying out Management of A and generation of EK B are performed. Certificate authority (C A) 45 1 Public presentation corresponding to the secret key which performs a signature to 2 and E KB which key issue center (KD C) generated and which both signed A key is published as a key for signature verification.
Key issue center (KD C) 45 1 E KB Request evening 4520 makes issue requesting of E KB to 1. E It is a rank in KB requester, for example, contents. It is related with the contents storing media which provide media, such as CD which carried out Payment, and DVD. Content provider (C P), Conten Pro which performs distribution of electronic Conten Tsu Four pines of storage systems, such as Bayda (C P) and a flash memory It is One to A. He is a storage system licenser etc. who provide the license to require.
These E KB Request evenings 4520, each media to provide and conte use of Tennis and a license is faced -- a needed key is obtained by EKB processing E KB set up as a key -- contents, media, and license format It matches and provides for When. EKB -- 1 issue S from E KB requester 4520 The 1 (KD C) -- 45 1 following the E K B issue requesting to 1 -- a key issue center (K D C) -- 45 1 1 generates.
EKB requester 452 0, 1 issue center (KD C) 45 1 1 is received. They are media manufacturer 4540 and device fabrication about E KB received as a result of issue requesting. Person 45 5 It provides to 0, E It is you about the media which stored KB, or a device. The processing supplied to THE is possible. these E KB (for example, one) -- or -- double -- In category Tree of a number, it is generated as E KB which can be processed.
In this system, it sets to plurality (for example, two) or three or more category Tree. Only in E K B which can be processed in common, and the only category tree, E K B etc. which can be processed, and E KB various type are generated, and become a situation used. It is such. It is the E KB type definition list which was list-ized about EKB various type.<sub>c</sub> 1 issue center (KD C) manages an EKB type definition list. EKB tie The latter part explains a A definition list in detail. E KB Request evening 452 0 is a key issue center about the demand of a E KB type definition list. (KD C) 45 1 It requires of 1. A The list is acquirable, It is a from key the case where there is data change of a list. Line center 1 (KD C) 45 1 It is notified from 1 to EKB requester 4520. To.
Top-level 'category' entity (TL CE) 453 0, it mentioned above It is a management entity of Category 1 which stands in a row at route Tree to obtain. Sabilli For key management of 1, and the E K B processing stored in management device I D and each device Node key - Setsu Correspondence list with device 'node' key (DNK) which is A It manages. device fabrication which manufactures the device corresponding to the device under management as opposed to person 4550 -- device and node . key for device storing -- raw -- Formation and offer processing are performed. [ (DNK) ]
Key issue Seng evening 1 (KD C) 45 1 When 1 receives £1^8 issue requesting from £1< 3 requester 4520, it is a key issue center. (KD C) 45 1 It is Follow to 1 and issue requesting. Ivy E KB is generated. E KB to generate is two top-level . categories. When it is E KB which can be processed in A dragon 1, It is Sending about substitute's EKB issue requesting to the two top-level' power Age' entity (TL CE) 4530. Trust is carried out, Tap level , category , and the entity (TL CE) which received substitute's E K B issue requesting -- 4530 -- the just device in each Category 1 -- a roux -- A crested ibis -- generating substitute EKB who can acquire Key issue center (KD C) 45 1 It transmits to 1. It carries out. key issue Seng evening 1 (KD C) 45 1 one which received 1 from T L C E -- again -- E K B is generated based on a plurality of substitutes EK B. EKB student based on substitute E KB The latter part further explains Formation processing.
Tap level , category , and entity (TL CE) 4530, EKB Li It is a E KB type definition squirrel like A question evening 4520. It is a 1 issue center about the demand of A. (K D C) 45 1 It can require of 1 and can acquire a list.
It is [ top-level' category' entity (TL CE) 4530 and ] further about the deletion demand of the type defined about self Tree of a E K B type definition list. 1 issue center (KD C) 45 1 It can require of 1. For example, other category Important point which deletes the EKB type defined as Lily and shared E KB from a list It is Request. Top-level 'category' Entity (TL CE) 4530 are a from key about changed information, when there is change about the self tree to manage further. Line center (KD C) 45 1 It notifies to 1. About these processings, it is business about a flow. It is and the latter part explains.
It is classified into device fabrication person 4550 and the device fabrication person of two kinds. It is a device node key one to the device to manufacture. (DNK) E both data of KB DNKE device fabrication person 45 who manufactures the stored device 5 it is 1 -- he is D NK device fabrication person 4552 who manufactures Depice which stored device node key (DNK) in another side and a device.
Drawing 48 -- a figure -- key issue Seng evening 1 (KD C) shown in 47, an EKB requester, and the top level 'category' entity [ (T L C E) ] -- the example of composition of its that -- Prozek figure It is shown by carrying out. Key issue center (K D C) E K B issue information processor, E K B Ricou For Esta, a E K B demand information processor and top-level . category entity (T L C E) are De in which encryption communication is possible fundamentally as a Category 1 management information processor. -- It is constituted as a Tha processing unit.
The information processor which constitutes each entity, and both entity besides its it It has a scrambling part which manages scrambling attestation and at large [ at the time of data communications ]. Scrambling Control about scrambling at large [, such as a control part on the staff, attestation processing, and encryption/decryption processing, ] It is a control part to perform. Key data, identification data, etc. which are needed in an internal memory, mutual recognition processing, encryption, decryption processing, etc. and various processings are stored. It is used in mutual recognition processing with one discernment De evening, for example, other entities, etc.
Data transfer which uses the key data etc. which were stored in the code/decoding section, and the internal memory Processing of the attestation processing at the time, encryption processing, decryption processing, verification of data, generating of a random number, etc. It performs.
however, it sets to the information processor as the E K B Request evening -- generation processing of a key Within a self-device, the composition which is not performed is also possible. In this case, style required for generation of a key It becomes omissible [ Component, for example, a random number generation device etc., ]. concrete -- E K B -- Included the roux which generated the To route key itself and generated it -- generation of E K B containing crested ibis 1 -- from key the information processor as the E KB Request evening required of a line center -- a roux -- crested ibis 1 -- raw -- Although the means for carrying out Formation is needed E the route key included in K B is not generated itself -- requiring generation processing of a route key of key issue center 1 Style accompanying key generation processing of a random number generation device etc. in the information processor as a E K B requester which requires the E K B generation containing the route key generated in the key issue center (K D C) of a key issue center Component is omissible.
Since important information, including the internal memory of a scrambling part, an encryption key, etc., is held, it is outside. It is necessary to make it the structure which is hard to read from a part unjustly. Therefore, tongue-proof which comprised a semiconductor chip for example, it had the structure which is hard to access from a scrambling part and the outside It is constituted as Paemonry.
To everything but each entity and the scrambling function of these, a central processing unit (C P U : Central Processing Unit) -- a (Random Access Memory) RAM^R 0 M(Read Only Memory)^input part, It has indicator and one De evening base I/F and a database. It is a function as a control system of central processing unit (CPU: Central Processing Unit), RAM (Random Access Memory), R O M (Read Only Memory), and each entity main part. It is a formation part to carry out. As the main memory memory for various processings in RAM and CPU It is used and is used as workspace for processing by C P *. As for ROM, the boot program in C P U, etc. are stored.
The database of an information processor or other memory hands which constitute each entity In the stage, If it is the data which each [ it / it ] entity manages, for example, a key issue center, (K D C), The management data about published E KB, and also E KB type definition Squirrel A etc. are stored, In the database of Tap level , category , and entity (TL C E), correspondence of management Depice and device node key (DNK) etc. -- the management data of the device belonging to category Tree is stored -- E KB Rique Database of the A evening About the management data which matched the relation with E KB currently used to offer Content and Content, and the offer place device of contents Management data etc. are stored. A E KB type definition list and EKB Ricou Esta and top-level 'category ■ Information place which constitutes entity (T L C E) The composition which is stored also in Device and changed into the state which can be referred to is preferred. Or EKB requester and Tap level - Category 'Entity (TL CE) is accessible. are . Web (Web) Sai which 1 issue center (KD C) manages As the composition put on A It is good.
Like and the device which were mentioned above, and EKB processing (decoding) It is device and node - to a sake. 1 (DNK : Device Node Key) is used. device - node . -- (DNK) which one device has -- a figure -- it explains using 49. Tree shown in Drawing 49 It is Ah with the leaf in which the device was matched for an example and the lowest stage in one category Tree. Ri (to for example, management Tree of top-level 'category' entity (T L C E)) It corresponds. In the upper row, Le 1 Tory (ex. eight-step composition) stands in a row. Node tree on the path from a device to [ here / as a device is shown in Drawing 49 ] the upper row It has 1. these Kisera using A as device 'node' key (DNK) -- Keep it has -- E KB is decoded using device 'node' key (DNK).
It is assigned so that being fundamental and one device may not overlap with one leaf. As an exception, it is for example, P C Sov. Sov, such as A When Toware is matched with a leaf All software' Padcage of one Ba 1 Jon are Asa to one leaf. An inn may be carried out. TL CE also determines this. That is, it is how about a device. It assigns to a leaf and T L C E decides which Node tree 1 to give.
Top-level , category , and entity (T LCE) offer of the device itself Contractor (maker 1) it is -- there is also a case -- as opposed to a manufacture device -- beforehand -- device - no -- storing Do key (DNK) -- it is offer to a user (sale) Carrying out is possible. That is, it is a certain specific category tree beforehand to devices, such as a recording and reproducing device. Set of a node key It stores in a memory by using A as device . node . key (DNK). It carries out and provides for a user. (sale) Carrying out is possible.
(E K B evening A definition list)
Although it is as having already explained E KB distribution in a category unit, Two or more To the device belonging to E KB common to a category, i.e., a different category tree, When it sets and E KB which can be processed is generated and published, some problems occur. It may carry out.
For example, media in which a certain re-writing is possible (recording medium) For example, Portable flash Formats of Fusumori Licensee of A (license receiver) It carries out, two companies where A company differs from B company exist -- media (portable flash memory) Licenser (licensor) it is -- maker 1 exists as a top-level category style which has Category Lolli which A company manages, and category Tree which B company manages in the bottom of it it sets to Formation -- A company and B company give compatibility to a mutual device -- various distribution contes In order to make it possible to use Tennis in common, Category Lolli of A company, and power of B company It processes in the affiliation device of two category Tree of Tegori 1. (decoding) E KB [ 'possible ] is generated and published in key issue center (KD C).
De of one device belonging to category Tree which A company manages in such a situation Vice-'node' key (DNK) is revealed, and it is striped U, Distribution whose use was enabled in the mutual device of A company and B company using the device node key (DNK) ' which a possibility that all Contents will be used for injustice will generate. Use Although the E KB update process as Lipoku processing is needed in order to eliminate, In this case, since E KB common to two Category Lolli of not the Revoke processing about the category tree of A company but A company and B company exists, it is necessary to perform a E KB update process about two category Tree, A company and B company.
Thus, when E KB common to a plurality of category Tree is generated and provided, Revoke processing within one category Tree, and not only a E KB update process but common It is necessary to perform the E K B update process accompanying Revoke in all other category Tree that use E KB to carry out. this -- for B company -- self To manage subject to the influence of other different management Category 1 from a To device -- processing -- negative a load increases -- intermediary Cause.
Category' Entite which manages each category for the permission authority of issue of E KB usable in common in a plurality of categories in order to solve such a situation It has composition which Í has. That is, in order to take compatibility, it belongs to a partner's category. Risk to one's device in a category Only when permissible, [ who is caused by the fault of a device ] A private seal and a risk can permit issue of E KB which takes compatibility. When there is nothing, issue of E KB usable in common or use shall not be accepted. When it tries to perform such processing, they are plurality (for example, two) or three or more Kate. In Gori lily, it is E K B which can be processed in common, In the only category Tree Situation which it is accepted, and E KB etc. which can be processed, and E KB various type are generated, and is used It becomes. It is the EKB tie which was list-ized about EKB such various type. A definition squirrel It is A. Drawing 5 It is a E KB type definition squirrel to 0. The example of A is shown. EKB tie Key issue Seng evening 1 (KD C) records a A definition list on a recording medium, and manages it. Offer or an inspection is possible if needed also to the E KB Request evening and TL CE. It sets in the state.
As shown in Drawing 50, it is a E KB type definition squirrel. A, "E KB type discernment casual flirtation -" "Node", Having each field of "explanation", a "E KB type discernment number" is, E KB type definition list -- squirrel Na which identifies E KB of various modes by which Up was carried out it is Hotel -- if discernment numbers differ -- Category which can process the EKB It has composition which differs in 1 or its combination.
They are the "node" field and the field which records top node I D of category Tree which can apply EKB. For example, E KB evening eve discernment number : As for EK B of 1, top node I D of Category 1 of MS (MemoryStick: memo listee A) is recorded. E K B type discernment number : As for E KB of 3, Tap node I D of the category tree of M S (MemoryStick: memo listee A) and top node I D of Category Lolli 1 of PH S are recorded.
"explanation" field and an EKB type definition list -- squirrel Up was carried out -- various It is the field which records explanation of EKB of a mode. For example, E KB type discernment nan Ba 1: E KB of 1 is MS (MemoryStick: memo listee A). It is EKB of for. Things are shown. EK B type discernment casual flirtation 1: EKB of 3 is common to the device of Category 1 of M S (MemoryStick: memo listee Dug) and P HS. It is shown that it is usable E KB.
E KB type definition squirrel shown in Drawing 50 A is a key issue center. (KD C) to manage. Encryption key enciphered by the key acquirable by processing of E KB Entity to which It was tries to perform encryption data distribution of encryption Content etc., example a For example content provider -- a figure -- referring to the E K B type definition list shown in 50 the EKB type which can be processed by category Tree containing the device which is the offer target of contents is chosen -- the E KB type discernment number is specified -- key issue S E KB generation processing is requested from A evening 1 (KD C).
however, the E KB registration processing various type to a E KB type definition list -- Tap level 'category' Entite of category Tree which serves as a candidate for registration if it is Recognition of Í (T L CE) is needed. For example, TL CE of category tree A -- A is other categories. If issue of EKB to share is refused, they will be category Tree A and other power. The type of EKB used as sharing of a Age tree is registered into an EKB type definition list. There is nothing.
For example, T L C E of category tree A -- A, T L C E of category Tree B -- B, T L C E of Category 1C -- It is if each of C approves issue of shared E KB, In these three Category Lolli, the type of common E K B which can be processed is the EKB evening. It registers with a A definition list, For example, contents pro Paida is Show about the registration type. A To E KB type discernment number is specified, and it is a key issue center. (KD C) EKB student It becomes possible to request Formation processing.
that is, a new E KB type is registered into a E KB type definition list -- in order [ corresponding to the EKB type ] to do the E KB type discernment number * definition of -- the following processing It is needed.
(1) Application pair of E KB corresponding to the E KB evening A discernment number made into definition Learn more All the T L CE which manages the category used as an elephant is EKB type registration requests. It sends to key issue center (KD C).
(2) Key issue center 1 (KD C) processes EKB used as the candidate for registration in a demand. E KB type registration request of the above [ all the Tap level 'category' entities of one or more possible category Tree (TL CE) ] checking having sent a new EKB type discernment number is defined after It was -- EKB type definition list It adds.
(3) In key issue center (KD C), there was change to an EKB type definition list. In order to tell things, they are all the T L C E and E K about a E KB type definition list change notice.
It sends to B requester.
A E KB type definition list is Sending et al. to all the T L C E and a E KB requester. Re and web (Web) Sai It is put on A and they are all the TL CE and E KB Rique. It is opened to the A evening. Therefore, T L CE and a E KB requester, and the newest E always
KB type definition squirrel When [ be / acquiring the E KB A type information registered into A / possible ] To.
(E KB type registration processing)
E KB type definition squirrel the time of registering a new E KB type into A -- key issue Seng the process flow explaining the processing which evening 1 (KDC) performs -- a figure -- 5 It is shown in 1. First, A 1 issue center (KD C) and EKB type registration Request from T L C E which makes a registration demand new E KB type A is received. (S 1 0 1) It carries out. category which registration demand E KB makes usable in common at the E KB type registration request from TLCE The number of Li is contained. I use key issue center (KD C) as the number of categories in a demand one. It is Acceptance about the same EKB type registration request from TL CE corresponding to the category of the number of To. It is judged whether it possessed or not. (S 1 02) It carries out, A number of category which are in agreement with the number of categories in a demand It is carried out on condition that the demand from T L C E corresponding to Li was received, E Register the new E KB type which followed the demand to KB type definition list, and perform the update process of a list, and renewal notice processing of a list (S 1 0 3). It is carried out to renewal notice processing, TLCE, and a E KB requester.
Thus, key issue center (KD C) EKB type definition squirrel A is received. In initial registration processing of a To E KB type identifier, Processing of the E KB type which is due to be registered Way which manages one or more category Tree selected as possible category Tree Category [ of The ] - It registers on condition of recognition of an entity.
it sets to processing of these -- accepting necessity in the communication between key issue center (KD C), TLCE, and the EK B Request evening -- code of mutual recognition processing and send data -izing processing is performed. It is good also as other message encryption processings, digital signature generation, and composition that performs verification processing. Authentication based on a public-key crypto system -- being certain -- it is holding a public key beforehand between each entity the case where encryption communication is performed -- Synthesis The necessary procedure is taken by obtaining.
(E KB type cancellation processing)
For example, all the apparatus belonging to a certain category must be Revoke(ed). At the time Top-level , category , and entity (T L C E) It is necessary to give the demand which cancels the E KB type used as an element to 1 distribution center 1 (KD C). The category The demand which cancels the EKB type registered now can be given to KD C for the reason of stopping top-level 'category' entity (TL CE), for example, a certain service.
the flow of this E KB type cancellation processing -- a figure -- it explains according to the process flow of 52. TL CE which makes a key issue center (KD C) and EKB type cancellation demand receiving (S 20 1) , -- carry out a E K B type cancellation request. T E KB type cancellation Request from L CE When A is received, it is a key issue center. (KD C) The Request It is a pipe about the category used as the element of the EKB type cancelled by A. After checking that TL CE which carries out Reason is an addresser of the request, EKB evening A definition squirrel The E K B type discernment number corresponding to the type specified in the cancellation request in A is cancelled, and it is a E KB type definition squirrel. A is updated and it is a list. Renewal notice processing (S 2 02) is performed. Renewal notice processings are T L CE and EKB Li. It is carried out to Questa.
Thus, key issue center 1 (KD C) It registers with an EKB type definition list. In the cancellation processing of a E KB type identifier carried out, E KB type which is due to be cancelled One or more category Tree selected as Category 1 which can be processed are managed. few -- Both -- being carried out on condition of the cancellation demand of one category entity -- cancellation processing It carries out. In this case, recognition of other category and entities is not needed. it sets to processing of these -- accepting necessity in communication between key issue center (KD C), TL CE, and a E K B requester -- code of mutual recognition processing and send data -izing processing is performed. It is good also as other message encryption processings, digital signature generation, and composition that performs verification processing. Authentication based on a public-key crypto system -- being certain -- it is holding a public key beforehand between each entity the case where encryption communication is performed -- Synthesis The necessary procedure is taken by obtaining.
(E K B type definition list change notice processing)
for example, it sets in a certain Category 1 -- device Revoke 1 Chillon (Depice exclusion) Device no which exchanges for a new thing DNK which a certain device stored It is the category about the processing to which the state in trees, such as renewal of Do key (DNK), is changed. When T L CE which manages a tree carries out, as opposed to the E KB requester or relation T L CE which is using E K B for those devices -- processing of these It is necessary to tell having happened.
because, it does not tell about it that device Revoke 1 Chillon happened -- conte Provider (CP) continues using old EKB, and enciphers contents -- Arrangement Supposing it carries out Trust Also in the device Revoke(ed) in old E K B, it is a E KB place. Reason (decoding) Because being possible, conte, and the illegal use of To may be continued It is. It is usually Place the case where vice-node key (DNK) is updated. Old D NK which recomes is thrown away, a device will have new D NK this -- new; a Content provider uses EKB corresponding to DNK -- it can kick The, The device with new DNK processes E KB. (decoding) It cannot carry out. It is because it will become impossible to access Ri and contents.
In order to avoid such evil,
* As results, such as device Revocation, change arises in evening Gupert of E KB. In the It was case
* as results, such as renewal of a device node key (DNK), -- few -- Both -- one opportunity Case where change arises in the value of DNK which a vessel has,
It is necessary to send TL CE and Tree change notice (Tree Change Notification) to 1 issue center (KD C) in these cases. In Tree change notice (Tree Change Notification), it registers with the E K B type definition list which requires change corresponding to registered E K B type discernment casual flirtation 1 and EKB type discernment casual flirtation 1 -- which -- what of the information which shows whether it is Has happened by a category, and Lipotech 1 Chillon and renewal of DNK -- To wake up The information whether it is It was is included.
E the flow of KB type definition list change notice processing -- a figure -- following the process flow of 53 -- opinion Ming is carried out. Key issue center (KD C) carries out a Tree change notice reception (S 30 1) from T L C E. If the Tree change notice from TL CE is received, it is key issue center 1 (KD C), E Extract the E K B type discernment number which has KB type definition list to the category in an element, To which E KB type discernment number, it is what kind of strange Y. (ex. Lipocaseion) Renewal of DNK (replacement) It happened. EKB type definition squirrel with information A A change notice is performed to TL CE and the EK B requester of All. In processing of these, mutual recognition processing and encryption processing of send data are performed if needed in the communication between key issue center 1 (KD C), TL CE, and the E KB Request evening. Other message codes It is good also as-izing processing, digital signature generation, and composition that performs verification processing. Public key It is between each A j tee tee the case where the attestation or encryption communication based on a code method is performed. Procedure which sets and holds each other's public key beforehand is performed.
(E KB type definition list demand)
Tap level 'category' entity (TL CE) and sub power other than TL C E Age' entity (S C E) Or E K B Ricou, such as a content provider In order to know the S evening and the E KB type definition list of the latest version, he is E KB type definition Li. Sending of a strike can be required of 1 issue center (KD C). key issue Sen evening - (KD C) receives this demand -- it is a demand about the EKB type definition list of the latest version It returns to a person.
the flow of EKB type definition list demand processing -- a figure -- following the process flow of 54 -- explain. Key issue center (KD C) receives a E KB type definition list demand from either TL CE, a subcategory' entity or a E KB requester. (S 40 1) It carries out. E reception of KB type definition list demand will extract a key issue center (K D C) and the newest EKB type definition list -- Ente which performed demand processing as opposed to Witi -- the newest E KB type definition squirrel A is transmitted (S 402). it sets to processing of these -- in communication between a key issue center (KD C), T LC E, a subcategory . entity, and a E KB requester, mutual recognition processing and encryption processing of send data are performed if needed. It is good also as other message encryption processings, digital signature generation, and composition that performs verification processing. public-key crypto system setting between each entity the case where the based attestation or encryption communication is performed -- beforehand -- Procedure which holds each other's public key is performed.
(EKB issue processing)
E It is based on issue . processing of KB, and the E KB issue requesting by an EKB requester, and is Done. To be. E KB Request evening,
[a] Content which provides CD, DVD, etc. and contents storing media Robaida (CP).
[b] Electronic information distribution (E CD : Electronic Content Distribution) Service Content provider who provides.
[c] Formats of a record system A holder.
The key acquired by decoding of Such and EKB is used and they are use of contents, and Fo. 1 Manyty which provides the service which enables use of A, media, and a device It is a tee.
Formats of the above-mentioned [c] record system In A holder,
[c 1] For example, Formats which stores E KB in a recording medium at the time of manufacture To Format which gives E K B which was set and was acquired for the manufacturing industry company of the recording medium Toda 1.
[c 2] For example, Formats which stores E KB in a storage device at the time of manufacture Format which gives EKB acquired for the manufacturing industry company of the storage device in Torda 1.
Formats of two kinds of of There is Toda 1.
E Explain the procedure of KB issue processing below.
(1) Creation of Maintenance 1
First, E KB requesters, such as a content provider, and self Cong that provides Content key used corresponding to Tengu, a device, and media is generated. For example, a E K B requester,
[a] Contrast which provides CD, DVD, etc. and Content storing media Robida (CP).
[b] Electronic information distribution (E CD : Electronic Content Distribution) Service Content provider to provide.
It comes out and, in a certain case, is,
In a contents key [ to generate ] and media top or electronic information distribution (E CD) service It sets and protects Content. (it enciphers) It is used as a key.
A E KB requester,
[c 1] Formats which stores E KB in a recording medium at the time of manufacture In A, it is an account. Formats which gives E KB acquired for the manufacturing industry company of recording media A holder.
It is Defense about Content which comes out and is recorded on Content key and its recording medium a certain case. To (it enciphers) It is used as a key.
A E KB requester,
[c 2] Formats which stores E KB in a storage device at the time of manufacture A smell Formats which gives The and E KB acquired for the manufacturing industry company of the storage device Toda 1. Conte which comes out and is recorded using Content key and its storage device in a certain case It is used as a (it enciphers) key which protects Tennis.
cryptographic algorithm for protecting contents using Content key etc. -- it can decide arbitrarily for each [ a mechanism and ] the format of every. (2) Generation of a route key
E KB requester is raw about the route key whose acquisition was enabled by decoding processing of E KB. Formation is carried out. a E KB requester does not generate a route key itself -- 1 issue Seng Generation may be requested from evening 1 (KD C). A route key is To protect about Maintenance 1. To (it enciphers) It is used for a sake. a roux -- using crested ibis 1 -- Maintenance 1 Mechanisms, such as a cryptographic algorithm for protecting, and each Formats every A -- duties Mind can be decided on.
(3) EKB issue requesting
An EKB requester sends the issue requesting of EKB to key issue center (KD C). this Request the route key and EKB of the above [ A ] -- a roux -- crested ibis 1 -- which -- One of the EK B type discernment numbers registered into the E KB type definition list whether to send to the apparatus of a category is contained. E Memory of KB requester and a self-device EKB type definition squirrel stored in the means A, Or The on a Netto work which can be perused It is based on the E KB type definition list acquired from A, and they are sirs, such as Content offer. The E KB evening eve which consists of a category containing the device used as the object which provides a screw is chosen. It carries out, It is E K B issue requesting about the E K B type discernment number which shows the selected E K B type. It is made to contain in inside and transmits to key issue Seng evening 1 (KD C).
(4) E KB issue processing
Key issue center 1 (KD C) is Based from a E KB requester to E KB issue requesting. When it comes and the route key is contained during E KB issue requesting, the roux -- EKB containing crested ibis 1 is generated and a route key is not contained during E K B issue requesting -- route key the case where a generation processing request is made -- KD C -- a roux -- crested ibis 1 is generated -- generation route key Included E KB is generated and it transmits to a E KB requester.
In EKB which key issue center 1 generates, and single category Tree, processing is possible. In the case where it is Noh EKB, and a plurality of category Tree, it may be E K B which can be processed in common. Key issue center 1 (KD C) is based on the E KB type discernment number contained in EKB issue requesting, composition important point of the E KB type discernment number The category used as base, i.e., a E KB type definition squirrel, it sets to A -- being specified A 1 Do recorded on no Dofi 1 Rudo of the It was E KB type discernment number is extracted.<sub>(</sub>Top node I D of the category tree is recorded on the node field. This is node I D corresponding to the management entity of the category Tree. This it is based on node ID -- it is management Entity of Category Lolli 1 Tobe Plebe as opposed to Le 'category' entity (TL CE) -- substitute's E KB issue requesting is advanced. The information which expresses each category as a route key is included in substitute's EKB issue requesting. TLCE which received sub EKB issue requesting from the key issue center (KD C), Inside of one or more specified categories (it does not Revoke) From each apparatus to last Substitute E K B with the composition which can obtain a route key-like is generated, and it transmits to a key issue center (KD C).
It has neither substitute EKB whom Tap level 'category' entity (TL CE) generates, a version number nor information for the verification (Version Check Value), and also is the usual EKB (refer to Drawing 6). It is a group of information with the same structure. using Leaf key 1 Doki 1 in substitute E KB here -- Node tree 1 A bar 1 crested ibis 1 of a higher rank Each T L C E (Format holder 1) in which the Argorism key length who enciphers, and the mode generate substitute E KB every -- it can decide arbitrarily. Thereby, they are other Fo. -- A An original security method can be used separately from A. Def Orr as A -- for example, -- Code Algorithm is decided to be triple D E S (Triple-DES) of FIPS46-2 -- T L C E which does not have an objection in this -- A Ripple D E S Al It is good also as composition which applies Gorism. T L C E -- arbitrary -- a cryptographic algorithm and key the apparatus which is under rule of other TLCE(s) about substitute EKB whom another TL CE also at the case where merit is decided made, and compounded EKB can also be processed -- as (code it turned) key of each, and predetermined length, for example, 1, Motorcycle six It is decided that it expresses with one De evening of A (16Byte). To. thus, Le predetermined when generating common EKB by a plurality of category Tree - Le is followed -- one key De evening of what position judging [ necessity or ] each apparatus of different category Tree become possible for themselves about the tag of E KB by setting up data. [ Forget and ] sand each of the key data contained in Walk E KB -- 1 Motorcycle six if it is A -- a self-device -- place it becomes possible to extract the key data in which Reason is possible one by one, and to process it -- final -- a roux -- a crested ibis -- it becomes possible to acquire --.
Namely, composition E KB generated based on substitute E KB and a plurality of keys 'De 1 Each of the evening has the composition stored in the fixed-length data field. Therefore, respectively An original algorithm and sub validation key block with original key' data length (sub EKB) Composition E KB generated by being based a plurality of encryption in substitute E KB re-arranging one data according to the node or leaf position in a key tree -- raw -- even if it accomplishes -- the tag of E KB -- Forget -- it becomes acquirable one by one about required key and data. such composition E KB and Network is passed -- it is -- it is storing to various recording media it carries out -- user (device) It receives, and is distributed or provided.
substitute E KB to whom key issue center (KD C) has been sent from T L C E -- Must it rearranges according to an important point -- it compounds -- adding a version number and the information for the verification -- Synthesis Accomplished composition EKB is completed and it transmits to the EKB Request evening. However, public key encryption Certificate authority (C A: Certificate Authority) different from the digital signature using art and key issue center (KD C) may be requested.
A figure is referred to for substitute's EKB generation, and generation of substitute EKB to composition EKB. It explains. Drawing 5 5, category TreeA, and 5 1 00, category tree B, and 52 0 In the processing which generates composition E K B common to 0, Category TreeA and 5 1 Substitute E KB whom T L C E of 00 generates -- It is a figure explaining the composition of (A). Substitute EKB - (A), category tree A, and 5 1 A route key is [ each device of 00 ] acquirable. are . It is generated as E K B. Roux Tori 1 field 5300 is mentioned above in a figure. Although explanation has explained as eight-step composition, in order to simplify explanation here, it has two-step composition.
Drawing 5 it sets to 5 -- triple figures which added the underline indicated in Tree composition numerical [XXX] shows tag in EKB (e, 1, r) -- the above-mentioned (figure 26 and a figure 27 reference) it carried out -- as e= l shows those with data, e = 0 shows those without data, branch nothing and 1 = 0 show those with a branch on the left to the left 1 = 1, in the right, r= l is branch nothing and r= 0 is a branch to the right. There is shown. a figure -- Category 1 of 55 alpha and 5 1 0 Each device of 0 (leaf) a roux -- crested ibis 1 the node key which each leaf stores in common in order to acquire -- a roux -- a crested ibis -- E KB which stored one De evening which enciphered -- may be generated. Each device is Drawing 5. Category TreeA of 5, and 5 1 0 Zero device node key (D NK) fields 5 1 2 Since the node key of each path of Tree of 0 is held, DNK field 5 1 The 20 best E KB which enciphered the route key by the node key of the stage may be generated.
Therefore, category TreeA and 5 1 0 Substitute EKB whom TL CE of 0 generates -- (A), Evening Gupert: 1 0 1 and 0 1 0 and 0 00 and 1 1 1 and 1 1 1, Kiepert : Substitute EKB set to E n c (K 0 1 0, Kr oo t) and E n c (K 0 1 1, kappa r omicron omicron t) - It is set to (A). Category tree A and 5 1 TLCE of 00, this substitute EKB -- (A) is transmitted to key issue center 1 (KD C).
Category 1B and 520 substitute E K B whom 0 generates -- (B) -- a figure -- it explains using 56. [ next, ] Category TreeB and 520 Each device of 0 (leaf) To the node key which each leaf stores in common in order to acquire a route key E KB which stored the data which enciphered the intermediary route key may be generated. each Deva a chair -- a figure -- 5 Category Tree B 5 of 6 since Node tree 1 of each path of A dragon 1 of device node key (DNK) field 5220 of 200 is held -- D NK field 5 2 EKB which enciphered the route key by the node key of the highest rung of 20 may be generated. Therefore, Category 1B and 520 Sub E KB which TL C E of 0 generates -- (B), Evening Gupa 1 A : 1 1 0 and 0 1 0 and 0 00 and 1 1 1 and 1 1 1, Kiepert : Substitute EKB set to E nc (K 1 1 0, K r o o t) and E nc (K 1 1 1, K r o o t) - It is set to (B). Category tree B, TL CE of 5200, this substitute EKB -- (B) is transmitted to key issue center (KD C).
Substitute EKB to whom each TL CE generated the key issue center -- (A) and substitute EKB - Composition EKB is generated from (B). generation of composition EKB -- a figure -- using 57 Explanation is carried out. Composition E KB is category TreeA and 5. 1 00 and Category -- B and 520 It is constituted as E K B whose acquisition of a route key the device belonging to each Rie of 0 enabled. Being fundamental and a plurality of substitutes' E KB received key data arrangement Composition E KB is generated by the work which is mixed and is arranged from the tree upper row. In the same stage, the data array which makes left-hand side the point is performed.
As a result, composition E KB Tag part : 1 00 and 0 1 0 and 0 1 0 and 00 0 and 0 00 and 1 11 and 1 1 1 and 1 1 1 and 1 1 1, 1 The 1 A : E nc (K 0 1 0, K r o o t), E It is generated as E K B with n c (K 0 1 1, K r o o t), E n c (K 1 1 0, Kr o o t), and E n c (K 1 1 1, Kr o o t). each 1 part key data was mentioned above -- as -- each, for example, 1, Motorcycle six By setting up as A, the one key De evening position which can be processed by a self-device is [ the device in each category tree ] detectable. it is -- since -- it becomes possible to acquire Le 1 crested ibis 1 from composition E KB.
The in case there is no device Revoke(ed) by any category Tree the above It is Revoke device although it is generation of The E KB, and the generation processing composition of composition E KB next. Generation of substitute E KB in case there is a chair, and generation of composition E KB are explained. Drawing 58, Category LolliA and 5 1 It is a Lipoku device to 00. (0 1 1 0 1) 5 1 It is a figure explaining generation of substitute E KB in case 50 exists. In this case Substitute E KB and Lipoku device (0 1 1 0 1) 5 1 5 Only 0 cannot be processed. Substitute EKB -- (alpha') It is generated by carrying out.
In this case, it is raw about substitute E KB with the key data composition which connected the path shown by the thick line of a figure. Formation will be carried out. Therefore, Category 1A and 5 1 Ding C E of 00 generates. Substitute EKB -- (A, :) Tag part : 1 0 1 and 0 1 0 and 0 00 and 1 1 1, 000, and 00 1 and 1 1 1 and 1 1 1, Kiepert : En c (K 0 1 0, Kr o o t), En c (K 0 1 1 1, K r o o t) and E n c (kappa0 1 1 00, Kr o o t) Becoming substitute It becomes epsilon KB - (A). Category TreeA and 5 1 of 100<sup>1</sup>0 transmit pound and this sub EK B - (A) to key issue center (KD C).
a key issue center -- every -- substitute E KB whom T L C E generated -- (alpha') (figure 5 6 reference) Revoke Category Tree without a device beta and 5 200 Substitute who received from TL C epsilon epsilon kappa beta 1 (beta) from -- composition epsilonkappabeta is generated. Composition About generation of epsilonkappabeta Drawing 5 It explains using 9. Composition E KB and category tree alpha and 5 1 00 Libor Device (0 1 1 01) 5 1 Device except 50, And category Tree beta and 520 As E KB whose acquisition of a route key the device belonging to Tree of 0 enabled It is constituted. Being fundamental and a plurality of substitutes' E KB received key data arrangement are mixed. Composition EKB is generated by the work arranged from the tree upper row. In the same stage The data array which makes left-hand side the point is performed.
As a result, composition E KB Tag part : 1 0 0 and 0 1 0 0 1 0, 000, 0 00 and 1 1 1, 000, and 1 1 1 and 1 1 1 and 00 1 and 1 1 1 and 1 1 1, Kiepert : E N C (K 0 1 0, K R O O T), E n c (K 1 1 0, K r o o t), E n c (K 1 1 1 , Kr o o t), E It is generated as E KB with n c (K 0 1 1 1, K r o o t) and E n c (K 0 1 1 0 0, Kr o o t). This composition EKB and category A dragon 1A and 5 1 00 Lipoku devices (0 1 1 0 1) 5 1 The device except 50 and category TreeB, and 52 The device belonging to Rie of 00 is Take about a route key. It is E KB which can be gained.
(5) Use of E KB
EKB which key issue Seng evening 1 (KD C) generated by the above processings is transmitted to the E KB Request evening.
For example, a E KB requester,
[a] Content which provides CD, DVD, etc. and contents storing media Robaida (CP).
[b] Electronic information distribution (E CD : Electronic Content Distribution) Service Content provider who provides.
It comes out and, in a certain case, is,
E Content key 1 is enciphered by a route key acquirable by KB -- Cong Teng enciphering the contents with which a user device is provided by luck 1 -- contents -- circulation -- To -- it becomes things. By this composition, it is to the specific category tree which can process E KB. The use of contents only of the device which belongs is attained.
The E K B Request evening,
[c 1] Formats which stores E KB in a recording medium at the time of manufacture In A, it is an account. Formats which gives E KB acquired for the manufacturing industry company of recording media A holder.
Encrypted Content Key is recorded by EKB out of which it came and which was generated a certain case, and a route key. Contents key with which the medium manufacturer was provided and which was enciphered by E KB and a route key Manufacture or oneself, it manufactures 'carries out and the stored recording medium circulates a recording medium. this -- Only device which belongs to specific category Tree which can process E KB by composition The encryption processing at the time of the contents record reproduction using E K B of the recording medium and decoding processing are possible. It becomes ability. A E KB requester,
[c 2] Formats which stores E KB in a storage device at the time of manufacture A smell Formats which gives The and E KB acquired for the manufacturing industry company of the storage device A holder. EKB out of which it came and which was generated in a certain case, and a roux -- it is record about Encrypted Content Key at crested ibis 1 Contents with which the device fabrication contractor was provided and which were enciphered by E KB and a route key manufacturing a storage device for the storage device which stored the key manufacture or oneself -- circulation It carries out. De which belongs to the specific category tree which can process EKB by this composition Only in vice, the encryption processing at the time of the contents record reproduction using E K B and decoding processing It becomes possible.
EKB will be published by the above processings. EKB issue Necessity is accepted in communication between each entity in a handling process, a E KB requester, and key issue center (K D C) T L CE, and it is the dark of mutual recognition processing and send data. Item-ized processing is performed. It is good also as other Messe 1 Di encryption processings, digital signature generation, and composition that performs verification processing. Authentication based on a public-key crypto system -- being certain -- it is holding a public key beforehand between each entity the case where encryption communication is performed -- Synthesis The necessary procedure is taken by obtaining.
(Example of composition which considers substitute E KB simple set as composition E KB)
it sets to the processing which generates composition E KB from substitute E KB who mentioned above -- the arrangement of the encryption key data contained in each substitute E KB is resulted [ from the upper row of whole Tree ] in the lower berth -- as -- Processing to rearrange was performed. next, thing for which such rearrangement processing is performed there is nothing -- the composition which stores in composition E KB substitute E KB whom TL C E of each Category 1 generated one by one as it is, and generates composition EKB is explained.
Drawing 60, Substitute E KB whom TLCE of a plurality of category Tree generated is remained as it is. Synthetic E KB 600 stored in the form It is a figure showing the example of 0. [ multiple ]
E it sets to issue processing of KB -- key issue center (KD C) EKB Request It corresponds to the E KB type discernment number specified by the evening, and he is E KB type definition Li. It is The to T L C E which is a management entity of Category Lolli 1 recorded on the strike. The generation demand of The E KB is published, Sub E KB 6 submitted from each T L C E 1 1 0 and 6 1 20 -- is only collected and it stores in composition EKB. however, opportunity belonging to each category Category to which the self-device in which a vessel can process the apparatus out of the composition E K B belongs corresponding substitute EKB can be chosen -- as size (ex. De-- evening length) 6 of each sub EKB portion 1 1 Day when 1 and its substitute EKB express whether it is for which categories the evening (ex. node I D) -- 6 1 1 2 is added.
To namely, substitute's E KB each selected as a candidate for storing, Sub EKB storing Node I D as the length which shows the data length of a field, and a node identifier of correspondence category Tree of each substitute E KB as sub E KB identification data is matched. It is stored. The number of substitutes EKB contained in composition EKB is header information 62. 0 It is added as 0. It signs based on all the data of composition E KB. (ex. signature of certificate authority ('CA)) 63 0 0 is generated and added.
this method is followed -- the above-mentioned figure -- composition E KB corresponding to the explanation using 57 is generated a figure -- composition E KB as shown in 61 will be generated. Sub E KB 6 1 1 Zero storing EKB, The which TLCE of category tree A explained in Drawing 55 generated The EKB -- It is the (A) itself, Evening Gupert : 1 0 1 and 0 1 0, 000, and 1 1 1 and 1 1 1, Kiepert : It is set to En c (K 0 1 0, Kr o o t) and En c (K 0 1 1, kappa r omicron omicron t). Substitute epsilon kappa beta 6 1 20 storing epsilon KB, Drawing 56 explains. Substitute E KB whom T L C E of category Tree B carried out generated -- It is the (B) itself, Tag part : 1 1 0 and 0 1 0, 000, and 1 1 1 and 1 1 1, Kiepert : It is set to E n c (K 1 1 0, Kr o o t) and En c (K i l l, Kr o o t).
the above-mentioned figure -- 58 and Drawing 5 Case where there is a Lipoku device explained using 9 Composition EKB turns into data composition shown in Drawing 62. Sub E KB 6 1 1 Zero storing EK B a figure -- 5 substitute E KB whom T L C E of Category 1A explained by 8 generated -- (alpha') it is the very thing -- substitute E KB -- (A), Tag part : 1 0 1 and 0 1 0, 000, and 1 1 1 and 0 00 and 00 1 and 11 1 and 1 1 1, Kiepert : E n c (K 0 1 0, Kr o o t), E It is set to n c (K 0 1 1 1, Kr oo t) and E n c (K 0 1 1 00, Kr o o t). Sub E KB 6 which has not generated a Revoke device 1 20 storing EKB, Drawing 5 T L C E of category tree B explained by 6 generated. Substitute E KB - It is the (B) itself, Tag part : 1 1 0 and 0 1 0, 000, and 1 11 and 1 1 1, Kiepert : It is set to E n c (K 1 1 0, Kr o o t) and E n c (K i l l : Kr o ot).
Desbats of self [ device / which belongs to each category by taking such composition ] Substitute EKB corresponding to the category to which a chair belongs is chosen and processed. (decoding) Carrying out It becomes possible. each category of every [ therefore, ] (TL CE) -- completely arbitrary code Argo a rhythm and key length are used -- substitute EKB is generable. Namely, other power It is not influenced by Age but TL C E can determine a cryptographic algorithm and key length. key issue center [ (KD C) ] -- an intermediary and every -- substitute EKB who collected from TL CE it decomposes, a tag and a key data portion are reconstructed, and it becomes unnecessary to carry out them -- load becomes light. substitute E K B of the category to which the apparatus which obtained E KB according to this method, and a him belong is found -- it is processing with the original way T L CE which manages a self-device defines it carrying out -- a roux -- crested ibis 1 can be obtained. in order to process other substitutes E K B it is not necessary to learn the method which TL CE of other categories defined -- again -- substitute EKB since the device of setting and denoting each key by fixed length is unnecessary -- theoretical -- which size It can use now also with a key.
(Ribo caseon processing -- (1))
Libor in the processing which used multiple E K B usable in common in the category The processing performed when generating The is explained below. Encryption contents A net It received from the outside by Network or media, and acquired by E KB. Revoke in the case of acquiring a contents key using a key and performing contents use Processing is explained first.
It explains, while referring to Drawing 63. Category 1A and 7 1 00 and Category 1B and E K B 700 which are used in common in 7200 Situation where 0 is used It assumes. Category TreeA and 7 1 0 0, category tree B, and 72 0 E KB7 used in common in 0 0 00 shall be defined as EK B type discernment casual flirtation 1#1 with the EKB type definition list.
it sets in such a situation -- a content provider, Network or Mede The contents enciphered by Content key by The are provided, Category LolliA and 7 1 Device belonging to 00, and category TreeB and 7200, EKB 7 0 0 Contents key by decoding processing according to acquisition of a route key, and a route key using 0 Acquisition and acquisition of the encryption contents by Content key are performed, and it is Content. It uses.
this situation -- category tree A and 7 1 Device A 1 belonging to 00, and 7 Key of 120 the situation in which unjust processings, such as disclosure of one De evening, are possible is revealed -- device A 1 and 7 Ribo of 120 -- suppose that The is performed.
In this case, category TreeA and 7 1 00 TL CE, as opposed to key issue center (K D C) -- A dragon 1 change notice (figure 5 3 reference) it performs -- being based on key issue center (K D C) and the received tree change notice -- each T L C E under management, and EKB Ricou It notifies to Esta. having received the notice at this time, and the Tree change notice it is only telling about -- the update process of an EKB type definition list is not performed.
The Tree change notice based on Ribo 1 The generating, Category which Revoke generated EKB Li as an entity who uses EKB which can be processed in A dragon 1 Only as opposed to Questa, Or category tree which Revoke generated further Category and Ente which manages other Category Lolli to which shared E KB is applied It is good also as composition performed only to Witi. It is a from key in order to perform this processing. Line center (KD C) and user squirrel of issued EKB As A, it is a E KB type. A discernment number and the E' KB requester using that EKB type are matched. It was squirrel A is held.
They are contents for the device of Category 1 which performed Revoke processing. Content provider as a E KB requester who is performing distribution, Libor Updated E KB which can be processed is generated only in devices other than for The processing. E KB issue requesting is made to key issue center (KD C) like. In this case, the content provider as the E KB Request evening, category TreeA, and 7 1 0 0, and Category 1B and 720 It is considered as the type of E KB used in common in 0. E KB type discernment number # 1 by which Definition is carried out is specified. New roux Crested ibis 1 is generated itself [ EKB Request evening ], and it sends to KD C, or is new Le. Generation of one crested ibis 1 is requested from KD C.
refer to the E KB type definition list based on key issue center (KD C) and E KB type discernment number # 1 which were specified -- node of a corresponding category tree being based -- Category 1A and 7 1 0 0, and Category 1B and 7200!<sup>1</sup>1^. In a just device, he is substitute E KB who can acquire to E about a new route key. Generation is requested.
category tree A and 7 1 0 0, category TreeB, and 72 Ding [ ] of 00 -- 0-pound each Substitute E KB is generated based on a request. In this case, category TreeA and 7 1 Device A 1 Revoke(ed) in 00, and 7 1 Other devices which eliminated 20 It only sets and he is substitute E KB who can acquire a new route key. -- (A) is generated. Category tree B and 720 In all the devices which belong to power Age if the device Lipoku(ed) in 0 does not exist, he is substitute E KB who can acquire new Le 1 Toky. -- (B) is generated and it transmits to key issue center 1 (KD C).
key issue center (KD C) is based on substitute EKB who received from each T LCE it generates in accordance with the method which mentioned composition E KB above -- generated E KB is transmitted to the E KB Request evening (ex. content provider).
E KB requester (ex. content provider) performs contents distribution with the application of new E KB received from key issue center (KD C). Are concrete. The contents enciphered by the contents key are provided and it is obtained by decoding of E KB. Content key is enciphered and provided by a To route key. Category TreeA and 7 1 Device belonging to 00, and category TreeB and 7200, EKB is used and it is a route. Acquisition of a key, acquisition of Content key by the decoding processing by a route key, and Cong Teng Acquisition of encryption Content by Dicks 1 can be performed, and Content can be used. However, category tree A and 7 1 Revoke device A 1 of 00, and 7 1 20 is updated. Since E KB carried out cannot be processed, use of Content becomes impossible.
If it sets to above-mentioned explanation, it is a key issue center. (KD C) From TL CE At the time, it is renewal of a E KB type definition list the case where A dragon 1 change notice is received. Although the example which does not perform processing was explained, When KD C receives a Tree change notice, key issue center (KD C) is based on tree changed information, E KB type definition Li the update process of a strike and an EKB update process are performed -- every -- an EKB requester and TLCE -- More It is good also as composition which sends the E KB type definition list by which new was carried out.
(Revocation processing 1 (2)) Next, it is the composition of having stored E KB in the storage device or the recording medium, for example, Record A user enciphers and records various contents to a medium, and it is encryption processing, Decoding place From E K B which stored in the storage device or the recording medium the key which is needed for Reason to acquisition The processing accompanying the Lipoku processing in the what is called its record type form which should use the route key carried out is explained.
It explains, while referring to Drawing 64. Category TreeA and 8 1 00 and Category Lolli 1B, situation where E K B 80* 0 used in common in 8200 is used It assumes. Namely, Category 1A and 8 1 00, category TreeB, and 82 0 In the storage device or recording medium used in common in 0, common E KB is stored -- Co by the contents encryption for which the user used E KB, and decoding processing It is assumed that Balance record reproduction is performed. Category TreeA and 8 1 0 0 and E KB800 which are used in common in category TreeB and 8200 With the E KB type definition list, the EKB type discernment number shall be defined as # 1 0.
this situation -- category TreeA and 8 1 Device A 1 belonging to 00, and 8 12 Key of 0 the situation in which unjust processings, such as disclosure of one De evening, are possible is revealed -- device A 1 and 8 Suppose that Lipo of 120 - The is performed. .
In this case, category tree A and 8 1 0 Zero T L C E, as opposed to key issue center (K D C) -- Tree change notice (figure 5 3 reference) it performs -- key issue center (K D C) is notified to each TL CE under management, and the related EKB Request evening based on the received tree change notice. This which received the notice at this time, and the Tree change notice It is only telling about and the update process of an EKB type definition list is not performed. T L C E of category Tree which performed Revoke processing, Revoke device A 1 and 8 1 the new contents processing using E KB in the future in 20 -- a stop -- To sake, as the oneself E KB Request evening -- devices other than for Revoke processing -- Only by being, E KB issue requesting is made to key issue center (KD C) so that updated E KB which can be processed may be generated. In this case, T LCE as a E KB requester, category tree A, and 8 1 0 In 0, and category TreeB and 8200 E KB type discernment casual flirtation defined as a type of E KB used in common -- # 1 is specified. A new route key is generated itself [ EKB requester ], and it sends to K D C, or requests generation of a new route key from KD C.
It is based on 1 issue Seng evening 1 (KD C) and E KB type discernment number # 1 which were specified, An EKB type definition list is referred to, Node of a corresponding category tree It is based and is category tree A and 8. 1 0 He is [ in / 0, and category TreeB and 8200 Ding and / a just device ] substitute E KB who can acquire about a new route key to O E. Generation is requested.
Category 1A and 8 1 Each of TL CE of 00, and category tree B and 8200 Substitute EKB is generated based on a request. In this case, category TreeA and 8 1 Device A 1 Revoke(ed) in 00, and 8 1 Other devices which eliminated 20 It only sets and he is substitute E KB who can acquire a new route key. -- (A) is generated. category TreeB and 820 in all the devices which belong to power Age if the device Lipoku(ed) in 0 does not exist -- a new roux -- sub E KB - which can acquire crested ibis 1 (B) is generated and it transmits to key issue center (KD C).
Key issue center (KD C) is based on substitute EKB who received from each T L CE. It generates in accordance with the method which mentioned composition E KB above, and transmits generated EKB to each TLCE (ex. Format holder 1).
every -- TLCE (e. format holder) distributes new E KB received from key issue Seng evening 1 (KD C) to each device -- renewal of EKB is performed. Category 1A and 8 1 00, category TreeB, and 820 It acquires using E KB which broke the record to the device belonging to 0, and the storage device of new Content. It performs as encryption processing to which Tall 1 crested ibis 1 is applied. New EKB is used and it is a code. Only when the -izing-recorded contents apply corresponding E KB, decoding of them is attained. By that, use becomes impossible in the Revoke(ed) device.
As mentioned above, it has explained in detail about the present invention, referring to a specific example. Carry out a deer. A person skilled in the art can accomplish correction and substitution of the example in the range which does not deviate from the gist of the present invention. To is obvious. That is, since the present invention has been indicated with the form of illustration, it is Ah. It should not be interpreted by Ri and the limited target. It is the beginning in order to judge the gist of the present invention. The column of the indicated claim should be taken into consideration. Industrial applicability
As mentioned above, according to the information processing system and method of like and the present invention which were explained, it is, Kate it is classified based on Gori -- Sabilli managed by category and the entity Constitute key Tree which carries out two or more owners of 1. The path which constitutes key Tree is chosen and chosen. E KB which consists of encryption processed data of the higher rank key by the low rank key on a path is generated. In the composition with which a device is provided, It is a basis to the E K B type definition list which matched an EKB type identifier and the identification data of one or more Category Lolli 1 in which EKB processing is possible. Since it constituted so that issue management of About E KB might be performed, E Consider it as KB generation demand person. The E KB requester of The can choose the category which serves as a candidate for application easily.
According to the information processing system and method of the present invention, it sets to the generation demand of validation keeping mouth A (E KB), The composition which generates a route key itself, and raw [ of a route key ] Since execution of the composition which requests Formation in the key issue Seng evening 1 was enabled alternatively, EKB student a Formation request person's reduction of incidence is realized -- EKB generation [ in / again / an EKB issue center ] Set. E category which is a category administrator about substitute's E KB generation at the time of a K B generation demand Since it had composition requested from the Li entity, the increase in efficiency of EKB generation and management processing is possible. It becomes ability.
According to the information processing system and method of the present invention, it is based on a category, and is a division. A part is carried out, which carries out two or more owners of the subTree managed by category and the entity One tree is constituted, The path which constitutes key Tree is chosen and it is a low rank key on a selection path. E KB which consists of encryption processed data of the higher rank key to depend is generated, and it is To provide to a device. In Configuration, To each of subTree set up as partial Tree of Keatuli 1 It sets and is a sub validation key block in which decoding processing is possible. (substitute EKB) It is a style about composition E KB. It accomplishes, Each of 1 and data in composition EKB is stored in a fixed-length data field. Since it had composition to carry out, even when substitute EKB by various algorithms is compounded Offer of E KB which can be decoded is attained in each device.
According to the information processing system and method of the present invention, it is based on a category, and is a division. A part is carried out, which carries out two or more owners of the subTree managed by category and the entity - Rie is constituted, The path which constitutes key Tree is chosen and it is a low rank key on a selection path. E KB which consists of encryption processed data of the higher rank key to depend is generated, and it is To provide to a device. In Configuration, To each of subTree set up as partial Tree of 1 Tree It sets and is a sub validation key block in which decoding processing is possible. (substitute EKB) It is a style about composition E KB. It accomplishes, Each sub validation key block stored in composition EKB (substitute EKB) Inner key Arrangement is held, and -- corresponding to each substitute E KB -- the data length of a sub E KB storing field -- The by various algorithms as composition which called and added sub EKB identification data Even when The E KB is compounded, offer of E KB which can be decoded is attained in each device.
Every citation, both waysCites: the store holds 7 of 8
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| WO0103364A1 | Cites | World Intellectual Property Organization (WIPO) | AE | International search |
| WO0103364A1 | Cites | World Intellectual Property Organization (WIPO) | AE | International search |
| WO0103365A1 | Cites | World Intellectual Property Organization (WIPO) | AE | International search |
| WO0103365A1 | Cites | World Intellectual Property Organization (WIPO) | AE | International search |
| US5748736A | Cites | United States of America | A | International search |
| US6049878A | Cites | United States of America | A | International search |
| JPH11187013A | Cites | Japan | A | International search |
16 members in 9 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 2000395844 | Japan | A | |
| 2000395844 | Japan | A | |
| 2000395844 | – | – | – |
| JP20000395844 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| WO02052780A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| JP2002198950A | Japan | A | |
| EP1249962A1 | European Patent Office (EPO) | A1 | |
| KR20030019317A | Republic of Korea | A | |
| CN1426642A | China | A | |
| US2003185396A1 | United States of America | A1 | |
| HK1058589A | Hong Kong, China | A | |
| EP1249962A4 | European Patent Office (EPO) | A4 | |
| US7346170B2 | United States of America | B2 | |
| CN100418316C | China | C | |
| KR100859622B1 | Republic of Korea | B1 | |
| EP1249962B1 | European Patent Office (EPO) | B1 | |
| AT444616T | Austria | T | |
| ATE444616T1 | Austria | T1 | |
| DE60140041D1 | Germany | D1 | |
| JP4581246B2 | Japan | B2 |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Wipo information: published in national officeWWP | WWP | |
| Wipo information: entry into national phaseWWE | WWE | |
| Wipo information: entry into national phaseWWE | WWE | |
| Wipo information: published in national officeWWP | WWP | |
| Wipo information: entry into national phaseWWE | WWE | |
| Wipo information: entry into national phaseWWE | WWE | |
| Designated statesAK | AK | |
| Designated countries for regional patentsAL | AL |
Numbers
- Publication
- 02/052780
- Publication, DOCDB
- 02052780
- Publication, EPODOC
- WO02052780
- Application
- 111236
- Application, DOCDB
- 0111236
- Application, EPODOC
- WO2001JP11236
Titles2
- English
- INFORMATION PROCESSING SYSTEM AND METHOD
- French
- SYSTEME ET PROCEDE DE TRAITEMENT D'INFORMATIONS
Classification
- CPC, 12
- H04L9/0822
- H04L9/08
- G11B20/00086
- G11B20/0021
- G11B20/00855
- H04L9/0836
- H04L9/0891
- H04L63/0428
- H04L63/062
- H04L63/0869
- H04L63/104
- H04L2209/60
- IPC, 8
- G06F21 00
- G06F21 10
- G06F21 62
- G11B20 00
- G06F12 14
- H04L9 08
- H04L29 06
- H04N7 167
Designated states24
- Regional, 20
- European Patent Office (EPO)
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- Türkiye
- National, 4
- China
- Republic of Korea
- Singapore
- United States of America