Abstract:
In the present invention, apparatuses are classified into a plurality of categories, and based on a media key and device key data held by apparatuses belonging to the respective categories, revocation data intended for revoking the device key held by a specific apparatus of the respective categories is generated for the respective categories, and recorded on a recording medium.
Abstract:
Information processing system and method for detecting a revoke entity by using an effecting key block (EKB). On the basis of the effective key block (EKB) used in a key distribution construction of a tree structure, a device or service provider is judged as a revoke (reject) entity. In a public key certificate, an ID for identifying the position of a hierarchical key distribution tree is stored, and a tracing is executed using a tag of the effective key block (EKB) on the basis of the ID acquired from the public key certificate, to judge whether or not the ID is at the position where an EKB processing (decoding) is possible and thereby to judge whether or not the entity corresponding to the ID is revoked.
Abstract:
In a content management method, content data is encrypted by a first key (TK), the first key is encrypted by plural types of second keys (MUK), the encrypted first key (Enc-TK) is multiply encrypted by a third key (MM), and the third key is encrypted by a fourth key (MMK). These encrypted content data (End-Contents), a medium key which is the first key (Enc-TK) encrypted by the second key and a move key which is a first key (Enc2-MM) multiply encoded by the second and third keys are recorded in a recording medium, the third key (Enc-MM) encrypted by the fourth key is recorded in a security region. This management method is managed by the move key and the medium key.
Abstract:
A format conversion apparatus is provided for converting a format of an information recording medium, comprising a section for reproducing coded encrypted title key information E'(Kti) stored on the information recording medium to generate encrypted title key information E(Kti), a section for encrypting the encrypted title key information E(Kti) using a random number MMi. to generate doubly-encrypted title key information E 2 (Kti); a section for encrypting the random number MMi using a second encryption key to generate an encrypted random number E(MMi), a section for recording the doubly-encrypted title key information E 2 (Kti) onto the information recording medium as coded doubly-encrypted title key information E 2 ' (Kti); and a section for recording the encryptedrandomnumber E(MMi) onto the information recording medium as coded encrypted random number E'(MMi).
Abstract:
A content key, an authentication key, program data along with an effective key block (EKB) are transmitted by an encryption key structure of a tree structure. The EKB has a structure in which a device constituting a tree leaf holds a leaf key and a limited node key. A specific effective key block (EKB) is generated and distributed to a group specified by a specific node, thus limiting an updateable device. A device not belonging to a group cannot be decoded, ensuring the distribution security of the key and so forth. Keys or data is distributed by an encryption key structure of tree structure, thereby providing an information processing system and method capable of efficiently and safely distributing data.
Abstract:
A record reproducing player and save data processing methods capable of insuring security of save data are provided. Save data is stored in a recording device, encrypted with the use of a program's individual encryption key, e.g., a content key, or a save data encryption key created based the content key, and when reproducing the save data a decryption process is conducted on it with the use of the save data decryption key particular to the program. Furthermore, it is made possible to create save data encryption keys based on a variety of restriction information, such as performing the storing and reproducing of the save data by conducting encryption and decryption on the save data with the save data encryption keys and decryption keys created with the use of a record reproducing player's individual key or a user's password.
Abstract:
In each digital content utilize session, a memory card generates conversion key information for specifying a data conversion, while a player generates inverse conversion key information for specifying an inverse data conversion. The memory card then performs the data conversion specified by the conversion key information on management information stored therein, and sends the converted management information and digital content stored therein to the player. The player performs the inverse data conversion specified by the inverse conversion key information on the converted management information to restore the management information, and utilizes the digital content in accordance with restrictions set in the restored management information to limit the use of the digital content.