摘要:
To provide a broadcasting system in which a content user can select CMs that he or she wants. A sub-content index-information presenting unit presents sub-content index information. A user selects in advance sub-contents that he or she wants to view, by referring to the sub-content index information, and views only the selected sub-contents.
摘要:
An encryption device, a decrypting device, a secret key generation device, a copyright protection system and a cipher communication device comprise: a CRL memory unit 111 that memorizes a CRL, a device key ring memory unit 112 that memorizes a peculiar device key KD A in every IC card 210a used in a decrypting device 200a, a content key memory unit 113 that memorizes a content key Kc which is a secret key for decrypting content, a hashing function processing unit 114 that calculates a hashing value of the CRL memorized in the CRL memory unit 111, an Ex-OR unit 115 that carries out an exclusive OR between the hashing value and the device key KD A memorized in the device key ring memory unit 112, and an Enc unit 116 that encrypts the content key Kc memorized in the content key memory unit 113 with an output value of an Ex-OR unit 115.
摘要:
A decryption key determining device that determines decryption key groups for use in decryption to be individually assigned to at least three terminals that obtain encrypted data and decrypt the obtained encrypted data, comprising a decryption key setting unit for associating each terminal with a leaf in a tree structure, and determining, for each node in the tree structure, decryption keys in correspondence with an invalidation state that indicates whether or not the terminal corresponding to a leaf that is reachable from the node is invalidated; and a decryption key group assignment unit for determining, for each terminal, a decryption key group to be assigned to the terminal, based on the decryption keys determined for each node that is on a path from the leaf corresponding to each terminal to a root in the tree structure.
摘要:
An encroption transmission apparatus and an encryption reception apparatus avoid attack that takes advantage of re-transmission request. A server apparatus encrypts a content key five times, thereby generating five encrypted content keys, calculates a hash value of the content key, and transmits the five encrypted content keys and the hash value. An image playback apparatus receives the five encrypted content keys and the has value, decrypts the five encrypted content keys thereby generating five content keys, calculates hash values each corresponding to the generated content keys, and compares the calculated hash values with the received hash value respectively. If at least one of the five calculated hash values matches the received hash value, the corresponding content key is considered correct. Conversely, if none of the five calculated hash values matches the received hash value, it is considered a decryption error.
摘要:
A content protection system prevents illegal key acquisition, without checking uniqueness of device keys. The content protection system includes a key data generation apparatus and a user terminal. The key data generation apparatus converts first key data, which is for using content, based on a predetermined conversion rule, thereby generating second key data, encrypts the second key data using a device key held by valid terminals, and outputs the encrypted key data. The user terminal obtains the encrypted key data, decrypts the encrypted key data using a device key held by the user terminal, thereby generating second key data, converts the second key data based on a re-conversion rule corresponding to the conversion rule, thereby generating the first key data, and uses the content with use of the generated first key data.
摘要:
A revocation list generation apparatus and a revocation judgement apparatus suppress the size of a CRL even if a number of public key certificates to be revoked increases.The revocation list generation apparatus, in which leaves in a tree structure correspond to public key certificates, which are identified by leaf identifiers, and nodes from a leaf that corresponds to a revoked public key certificate to a root are revoked, generates, for each revoked node excluding leaves, revocation information showing whether directly subordinate nodes are revoked, and generates a revocation list that includes a plurality of pieces of revocation information arranged in an particular order.The revocation judgement apparatus obtains the revocation list, attempts to construct a path from the root to the leaf, using the revocation information in the revocation list, and when the leaf is included in the constructed path, judges the obtained public key certificate is revoked.
摘要:
Provided is a content distribution system that prevents different keys to be derived between an encryption apparatus and a decryption apparatus. A random-number generating unit 112, in an encryption apparatus 110, generates a random number s. A first function unit 113 generates a functional value G(s) of the random number s, and generates a random-number value u and a shared key K from the functional value G(s). An encryption unit 114 generates a first cipher text c1 of the random number s, using a public-key polynomial h and the random-number value u. A decryption unit 123, in a decryption apparatus 120, decrypts the first cipher text c1 using a secret-key polynomial f, to generate a decryption random number s'. A second function unit 126 generates a functional value G(s') of the decryption random number s', and generates a random-number value u' and a shared key K' from the functional value G(s'). A comparison unit 127 generates a first re-cipher text c1', using the random-number value u' and the shared key K', and outputs the shared key K' if the first cipher text c1 is equal to the first re-cipher text c1'.
摘要:
Technology for suppressing the data volume of a TRL (terminal revocation list), which is information specifying terminals to be invalidated, in a system structured from a plurality of terminals, a distribution device for acquiring the TRL and distributing data to only those terminals that are not to be invalidated, and a management device for generating the TRL. This object is realized by a system structured from a management device, a content key distribution device and a plurality of terminals. The management device generates and transmits a TRL formed from data that expresses terminal IDs of all terminals to be invalidated (i.e. terminals whose IDs have a common bit string), by only a value and a position of the common bit string in the IDs, to the content key distribution device. Each terminal holds a terminal ID that includes a manufacturer ID, a serial number and the like, and requests the distribution of a content key by sending the terminal ID to the content key distribution device. The content key distribution device refers to the TRL, judges whether the terminal ID transmitted from the terminal is that of an invalidated terminal, and if negative, encrypts and transmits the content key to the terminal.
摘要:
A revocation list generation apparatus and a revocation judgement apparatus suppress the size of a CRL even if a number of public key certificates to be revoked increases.The revocation list generation apparatus, in which leaves in a tree structure correspond to public key certificates, which are identified by leaf identifiers, and nodes from a leaf that corresponds to a revoked public key certificate to a root are revoked, generates, for each revoked node excluding leaves, revocation information showing whether directly subordinate nodes are revoked, and generates a revocation list that includes a plurality of pieces of revocation information arranged in an particular order.The revocation judgement apparatus obtains the revocation list, attempts to construct a path from the root to the leaf, using the revocation information in the revocation list, and when the leaf is included in the constructed path, judges the obtained public key certificate is revoked.