摘要:
An access management system such as an AACS is used to protect highly confidential information. A specific content is deleted from a medium on which reco=ded are one or more contents or objects being encrypted using an encryption key (or Title Key) according to the AACS. When the contents are to be deleted (ST400), the contents and the encryption key will be deleted simultaneously (ST404), provided that the information medium does not record another content or another object encrypted using an encryption key which is equivalent to the encryption key used for encrypting the contents to be deleted (ST402N).
摘要:
According to one embodiment of the invention, there is provided an information recording and reproducing apparatus (200) which records information in a recording medium (100) and reproduces information recorded in the recording medium, the information recording and reproducing apparatus characterized by comprising a first recording section which records in the recording medium (100) an encrypted encryption key aggregate (TKF) where at least one encryption key (TK) for encrypting each of a plurality of pieces of information (contents) has been encrypted and registered and information (E-contents) encrypted using the encryption key (TK), a second recording section which records encrypted first private key information (Read Write MKB) used to encrypt or decrypt the encryption key (TK) into the recording medium (100) and which, if the encrypted encryption key aggregate (TKF) has not been recorded in the recording medium (100), records the first private key information (Read Write MKB) into the recording medium (100) only when the encrypted encryption key aggregate (TKF) is recorded in the recording medium (100).
摘要:
An electronic appliance (52; 62) is disclosed, the appliance comprising a disk drive (80; 80') configured to read protected information from a removable storage medium (100), an input (88) for receiving user requests, a protected processing environment (164) communicatively coupled to the disk drive, the protected processing environment being configured to: (a) access control information from the storage medium, the control information specifying one or more permitted or prohibited uses of the protected information; (b) apply the control information to govern access to or other use of the protected information; (c) use one or more decryption keys stored within the protected processing environment to decrypt one or more encrypted content decryption keys; and (d) use the one or more content decryption keys to decrypt the protected information, and an output (90; 160) for presenting the protected information to a user.
摘要:
A system for converting analog signals to digital signals with rights management protection is disclosed, the system comprising a device configured to receive an analog signal, convert the analog signal to a digital signal, and write the digital signal to a storage medium. The device includes a protected processing environment configured to detect analog control information embedded in the analog signal, generate digital control information based at least in part on the analog control information, and associate the digital control information with the digital signal.
摘要:
A rights management arrangement for storage media such as optical digital video disks (DVDs, also called digital versatile disks) provides adequate copy protection in a limited, inexpensive mass-produceable, low-capability platform such as a dedicated home consumer disk player and also provides enhanced, more flexible security techniques and methods when the same media are used with platforms having higher security capabilities. A control object (or set) defines plural rights management rules for instance, price for performance or rules governing redistribution. Low capability platforms may enable only a subset of the control rules such as controls on copying or marking of played material. Higher capability platforms may enable all (or different subsets) of the rules. Cryptographically strong security is provided by encrypting at least some of the information carried by the media and enabling decryption based on the control set and/or other limitations. A secure 'software container' can be used to protectively encapsulate (e.g., by cryptographic techniques) various digital property content (e.g., audio, video, game, etc.) and control object (i.e., set of rules) information. A standardized container format is provided for general use on/with various mediums and platforms. In addition, a special purpose container may be provided for DVD medium and appliances (e.g., recorders, players, etc.) that contains DVD program content (digital property) and DVD medium specific rules. The techniques, systems and methods disclosed herein are capable of achieving compatibility with other protection standards, such as for example, CGMA and Matsushita data protection standards adopted for DVDs. Cooperative rights management may also be provided, where plural networked rights management arrangements collectively control a rights management event on one or more of such arrangements.
摘要:
A method and apparatus for recording data on and/or reproducing data from a storage medium are provided. The recording apparatus includes an authenticating unit which authenticates a host , which transmits a write command to the apparatus, to verify whether the host is authentic; at least one job module which generates output information by processing the user data , which is included in the write command, based on disc information stored in the storage medium and device information stored in the apparatus, in response to the write command; a module selecting unit which selects the job module based on module selection information and sends the write command to the selected job module, when the host is determined to be authentic, the module selection information being contained in the write command and specifying the job module; and a recording unit which records the output information on the storage medium.
摘要:
The invention relates to an information carrier for holding user information, the information carrier comprising access information for accessing the user information, the access information being stored in a pre-determined first region on the information carrier. The information carrier further comprises at least one further region different from the first region, the further region comprising dummy information. The invention is based on the insight that the noise level of a read out signal increases somewhat in the region(s) where the access information is hidden. To avoid this difference in noise level between regions with and without the access information, this access information is assigned for only a specific region of the information carrier, but dummy information is also written in other regions. Due to this, an improved copy protection system against illegal read out of the user information present or to be present on the information carrier is realized.
摘要:
A system is described for protecting digital content stored (112) on a storage medium (108) from unauthorized copying. The system includes a number generator to generate a nonce, an encryption subsystem (114) and a decryption subsystem (128). The encryption subsystem encrypts data accessed from a storage medium containing a key distribution data block (MKB,110) using an encryption bus key (124) prior to transmitting the encrypted data via a data bus (106). The encryption bus key is derived based on at least a portion of the key distribution data block (110), at least one device key (116) assigned to the encryption subsystem and the nonce generated by the number generator. The decryption subsystem is coupled to the data bus to decrypt the encrypted data received over the data bus using a decryption bus key (140) derived based on at least a portion of the key distribution data block, at least one device key (130) assigned to the decryption subsystem and the nonce generated by the number generator.
摘要:
A device key 46 is implemented on a drive 4 side. To securely transmit the device key 46 to a host 5, the device key 46 is encrypted with a bus key. The host 5 side decrypts the device key with the bus key. A medium unique key calculating block 55 calculates a medium unique key with an MKB 12, a medium ID, and the decrypted device key 46. When the calculated medium key is a predetermined value, the drive 4 is revoked and the process is stopped. The medium unique key is supplied to an encrypting/decrypting module 54. A content key is obtained with an encrypted title key 14 and a CCI 15. With the content key, an encrypted content is decrypted and a content that is recorded is encrypted.
摘要:
A content stored in an information recording medium is managed on a per unit basis and protected from unauthorized use. The content stored in the information recording medium is divided into units, and the content is encrypted with a unit key generated for each unit. A unit key generation key is generated based on a variety of key generation information. The unit key for each unit is generated by applying a record seed corresponding to each unit to the unit key generation key. For example, a block key is generated based on the unit key and a block seed per block unit set for every 3 sectors. An encryption process is performed on a per block unit basis using the block key. During decryption, the decrypting of the content is permitted conditional on the matching in the key generation information, the record seed, and the block seed stored in a disk. Unauthorized use of the content is thus prevented.