DEVICE AND METHOD FOR KEY BLOCK BASED AUTHENTICATION
    21.
    发明申请
    DEVICE AND METHOD FOR KEY BLOCK BASED AUTHENTICATION 审中-公开
    基于密钥块验证的设备和方法

    公开(公告)号:US20100161972A1

    公开(公告)日:2010-06-24

    申请号:US11993262

    申请日:2006-06-26

    IPC分类号: H04L29/06

    摘要: The invention relates to a device (250) and a method for key block based authentication. In order to overcome the problems of known devices and method for authentication and to allow for an effective key block and/or application revocation wherein it is ensured that valid and new revocation information reaches said device and is used for authentication, a device (250) for a key block based authentication is proposed comprising authentication means (252) for authenticating between said device (250) having revocation information (254) and an application unit to be authenticated having a key block (AKB) by means of said revocation information (254) and said key block (AKB), and internal trigger means (256) for triggering a process of renewing of said revocation information (254).

    摘要翻译: 本发明涉及一种用于基于密钥块的认证的设备(250)和方法。 为了克服已知设备的问题和用于认证的方法,并且允许有效的密钥块和/或应用撤销,其中确保有效和新的撤销信息到达所述设备并用于认证,设备(250) 提出了一种基于密钥块的认证,包括认证装置(252),用于通过所述撤销信息(254)在具有撤销信息的所述设备(250)和具有密钥块(AKB)的待认证的应用单元之间进行认证 )和所述密钥块(AKB)以及用于触发更新所述撤销信息的过程的内部触发装置(256)。

    CONTROLLING DISTRIBUTION AND USE OF DIGITAL WORKS
    22.
    发明申请
    CONTROLLING DISTRIBUTION AND USE OF DIGITAL WORKS 审中-公开
    控制分布和使用数字工作

    公开(公告)号:US20090276635A1

    公开(公告)日:2009-11-05

    申请号:US11721060

    申请日:2005-12-07

    IPC分类号: G06F21/24 G06F21/00

    摘要: In order to efficiently prevent the save-and-restore attack on usage rights associated with digital work, these usage rights are protected by a hidden channel. In order to make it a difficult or expensive to manipulate the hidden channel, a device is proposed comprising: writing means (34) for writing on a record carrier (20) said digital work (DW) and attached usage right information (22) defining one or more conditions to be satisfied in order for the usage right to be exercised,—fingerprint extraction means (23) for deriving fingerprint data (24) from physically uncontrollable, changeable non-uniformities on said record carrier (20), and authentication means (25) for generating authentication data (26) from said fingerprint data (24) and said usage right information (22), said authentication data being provided for authenticating said usage right information, said writing means (34) being adapted for writing said authentication data (25) on said record carrier (20).

    摘要翻译: 为了有效地防止与数字作品相关的使用权的保存和恢复攻击,这些使用权利被隐藏的信道保护。 为了使操作隐藏通道变得困难或昂贵,提出了一种设备,包括:写入装置(34),用于在记录载体(20)上写入所述数字作业(DW)和附加的使用权信息(22),其定义 为了使用权被行使而要满足的一个或多个条件, - 指纹提取装置(23),用于从所述记录载体(20)上的物理上不可控制的,可变的非均匀性导出指纹数据(24);以及认证装置 (25),用于从所述指纹数据(24)和所述使用权信息(22)生成认证数据(26),所述认证数据被提供用于认证所述使用权信息,所述写入装置(34)适于写入所述认证 所述记录载体(20)上的数据(25)。

    Conditional access
    23.
    发明授权
    Conditional access 失效
    有条件访问

    公开(公告)号:US07403618B2

    公开(公告)日:2008-07-22

    申请号:US10024739

    申请日:2001-12-19

    IPC分类号: H04N9/67 H04N7/16 H04N5/275

    摘要: A transmitter provides receivers conditional access to data transmitted via a network. A content encryptor is used to encrypt the data under control of a same authorization key before it is transmitted to all receivers. The transmitter has a storage with a plurality of device keys. A further encryptor is used for producing a key block with a plurality of entries, where each entry is associated with a respective one of the device keys. At least some of the entries contain a representation of the authorization key encrypted with the associated device key. The transmitter transmits the same key block to all receivers.The receiver has a subset of the device keys. A first decryptor is used to retrieve the authorization key by decrypting at least one entry of the key block that is associated with one of the device keys of the receiver. A second decryptor is used for decrypting the data under control of the authorization key.

    摘要翻译: 发射机提供接收机对通过网络传输的数据的条件访问。 内容加密器用于在相同授权密钥的控制下将数据加密到所有接收者之前。 发射机具有具有多个设备密钥的存储器。 另一加密器用于产生具有多个条目的密钥块,其中每个条目与相应的一个设备密钥相关联。 至少一些条目包含用关联的设备密钥加密的授权密钥的表示。 发射机向所有接收机发送相同的密钥块。 接收机具有设备密钥的子集。 第一解密器用于通过解密与接收器的设备密钥之一相关联的密钥块的至少一个条目来检索授权密钥。 第二解密器用于在授权密钥的控制下解密数据。

    Optical device having second arrayed waveguide grating for temperature control
    24.
    发明授权
    Optical device having second arrayed waveguide grating for temperature control 失效
    具有用于温度控制的第二阵列波导光栅的光学装置

    公开(公告)号:US06477294B1

    公开(公告)日:2002-11-05

    申请号:US09671913

    申请日:2000-09-28

    IPC分类号: G02B628

    CPC分类号: G02B6/12014 G02B6/12019

    摘要: An optical device for multiplexing/demultiplexing optical wavelength signals comprises arrayed waveguide grating devices. To one thereof an optical signal, e.g. one of the optical wavelength signals or an optical signal from a reference source, is input so that its corresponding output signal can be used as a temperature control signal for a temperature control means of the waveguide device. Thus optimization for one optical wavelength signal automatically leads to optimization of all other optical wavelength signals.

    摘要翻译: 用于复用/解复用光波长信号的光学装置包括阵列波导光栅装置。 其中一个光信号,例如。 输入光波长信号中的一个或来自参考源的光信号,使得其相应的输出信号可以用作波导装置的温度控制装置的温度控制信号。 因此,对于一个光波长信号的优化自动导致所有其它光波长信号的优化。

    Method and system for providing copy-protection on a storage medium and storage medium for use in such a system
    26.
    发明授权
    Method and system for providing copy-protection on a storage medium and storage medium for use in such a system 有权
    在这种系统中使用的存储介质和存储介质上提供防拷贝的方法和系统

    公开(公告)号:US08296582B2

    公开(公告)日:2012-10-23

    申请号:US11674490

    申请日:2007-02-13

    IPC分类号: G06F11/00 H04L9/32

    摘要: In a method for providing copy-protection services on a storage medium (for instance a solid state memory module), the data are arranged in sectors to which a field (S4T) is associated, where said field contains a random value Ri which is changed randomly when writing data to said sector. By encrypting the data stored on the medium using a key which depends critically on said random numbers, bit-by-bit copies (apart from said random numbers, which can not be deterministically changed by an application) to a second storage medium or recopies from some intermediate storage medium, can not be decrypted because the values of said random numbers will have changed, thus preventing unauthorized duplication and replay attacks.

    摘要翻译: 在用于在存储介质(例如固态存储器模块)上提供复制保护服务的方法中,数据被布置在与场(S4T)相关联的扇区中,其中所述字段包含被改变的随机值Ri 在将数据写入所述扇区时随机。 通过使用严格依赖于所述随机数的密钥对存储在介质上的数据进行加密,将第二存储介质的逐位副本(除了不能由应用确定性地改变的所述随机数除外)排除 一些中间存储介质不能被解密,因为所述随机数的值将改变,从而防止未授权的复制和重放攻击。

    Secure Host Interface
    27.
    发明申请

    公开(公告)号:US20080189794A1

    公开(公告)日:2008-08-07

    申请号:US11814010

    申请日:2006-01-13

    IPC分类号: G06F21/00

    摘要: The present invention relates to a digital rights management system (40) for controlling access rights to copy protected content comprising an application unit (1, 21, 41) and a drive unit (3, 23, 43), to an application unit (1, 21, 41), to a drive unit (3, 23, 43) and to a corresponding digital rights management method. In order to allow an increased security in the management of digital rights, wherein in particular a “filter-driver”-hack is made impossible or is at least substantially complicated and a reliable confirmation about a command given in respect of digital rights and its execution, a digital rights management system (40) is proposed wherein said application unit (1, 21, 41) comprises a key storage unit (45) for storing a bus key (KB), a request generation unit (47) for generating a request (7, 27) to be carried out by said drive unit including a message regarding said access rights and a challenge (RX), a communication unit (51) for transmitting said request (7, 27) and for receiving a response (13, 33) to said request (7, 27) from said drive unit (3, 23, 43), a response verification unit (49) for verifying a link between said request (7, 27) and said response (13, 33) by decoding said response (13, 33) using said bus key (KB) and by checking for the presence of an indication of said challenge (RX) in said response (13, 33) and said drive unit (3, 23, 43) comprises a key storage unit (55) for storing a bus key (KB), a communication unit (51) for receiving a request (7, 27) including a message regarding said access rights and a challenge (RX) from said application unit (1, 21, 41) and for transmitting a response (13, 33) to said request (1, 21, 41), a request processing unit (57) for verifying said request (7, 27) and processing said message, a response generation unit (59) for generating said response (13, 33) including an indication of said challenge (RX) and a reply to said message, wherein said indication of said challenge (RX) and said reply are cryptographically linked by means of said bus key (KB) and wherein indication of said challenge (RX) in said response (13, 33) indicates that said request has been carried out.

    Method and device for adding or extracting a secondary information signal to/from a RLL code sequence
    30.
    发明授权
    Method and device for adding or extracting a secondary information signal to/from a RLL code sequence 失效
    用于向/从RLL码序列添加或提取辅助信息信号的方法和装置

    公开(公告)号:US07038600B2

    公开(公告)日:2006-05-02

    申请号:US09929265

    申请日:2001-08-14

    摘要: A method and device for adding or extracting a secondary information signal to/from a runlength-limited code sequence, includes detecting a polarity of a runlength at a first predetermined position of the runlength-limited code sequence and setting a parameter reflecting the degree of freedom that is present in the runlength-limited channel code, e.g., the selection of a merging bit pattern in the CD-standard, on the basis of the detected polarity so as to obtain a predetermined polarity of a runlength at a subsequent second predetermined position of the runlength-limited code sequence. The predetermined polarity then corresponds to a binary value of the secondary information. Thus, a side-channel with a small capacity is provided, which is positioned very close to the physical channel such that the secondary information is hard to be detected from the EFM bit stream. Therefore, the side-channel can be used as a hidden channel for copy protection purposes.

    摘要翻译: 一种用于向游程长度限制代码序列添加或提取辅助信息信号的方法和装置,包括检测游程受限码序列的第一预定位置处的游程长度的极性,并设置反映自由度的参数 存在于游程长度限制信道码中,例如,基于检测到的极性来选择CD标准中的合并位模式,以便获得在随后的第二预定位置处的游程长度的预定极性 运行长度限制代码序列。 预定的极性然后对应于辅助信息的二进制值。 因此,提供了具有小容量的侧信道,其被定位成非常接近物理信道,使得从EFM比特流难以检测到辅助信息。 因此,侧信道可以用作隐藏通道,用于复制保护。