Data protection system that protects data by encrypting the data

    公开(公告)号:US07395425B2

    公开(公告)日:2008-07-01

    申请号:US10297089

    申请日:2002-03-28

    摘要: A data protection system is provided that reduces, to a degree, the amount of encrypted data that is distributed to a plurality of terminals. In the data protection system a terminal whose decryption keys are exposed by a dishonest party is made to be unable to decrypt the data correctly, while other terminals are able to decrypt the data correctly.The data protection system includes a plurality of terminals, and an encryption device that encrypts distribution data distributed to each terminal. Each terminal is corresponded with one node on a lowest level of a 4-ary tree structure or the like having a plurality of hierarchies. The data protection system, for each node in the tree structure, excluding those on the lowest level, determines a plurality of combination patterns that include combinations of two or more of all four nodes that are reached one level below the node, decides an individual decryption key for each determined combination pattern, and decides an individual decryption key for each node on the lowest level. Further, the data protection system has each terminal store all decryption keys decided for the nodes on the path from the node on the lowest level that corresponds to the terminal through to the node on the highest level. The data protection system prescribes nodes that are reached from the node on the lowest level that corresponds to the terminal through to the node on the highest level that correspond to a terminal that has been dishonestly analyzed as invalid nodes. For invalid nodes, other than invalid nodes on the lowest level, the data protection system designates an encryption key that corresponds to the decryption key decided in correspondence with the combination pattern that combines all nodes, excluding invalid nodes, of the four nodes that are reached one level below the node, and has the encryption device encrypt distribution data that uses each of the designated encryption keys.

    Copyright protection system, recording device, and reproduction device
    42.
    发明申请
    Copyright protection system, recording device, and reproduction device 审中-公开
    版权保护系统,记录装置和再现装置

    公开(公告)号:US20080044017A1

    公开(公告)日:2008-02-21

    申请号:US11503180

    申请日:2006-08-14

    IPC分类号: H04N7/167

    摘要: A copyright protection system includes a recording device and a reproduction device. The recording device writes encrypted content, an encrypted content key for decrypting the encrypted content, and license information on a recording medium on which a unique media number has been recorded in an unrewritable state. The license information is generated using both the media number and the encrypted content key, and therefore reflects both values. The reproduction device reads the media number, the encrypted content key, and the license information from the recording medium, and judges whether the license information reflects both the media number and the encrypted content key. The reproduction device decrypts the encrypted content key, and decrypts the encrypted content using the content key only if the license information reflects both values. Thus, the copyright protection system allows only original recording media to be reproduced, and prohibits reproduction of copy recording media.

    摘要翻译: 版权保护系统包括记录装置和再现装置。 记录装置将加密内容,用于解密加密内容的加密内容密钥以及在不可重写状态下记录了唯一媒体号码的记录介质上的许可信息进行写入。 使用媒体号和加密的内容密钥来生成许可信息,因此反映这两个值。 再现装置从记录介质读取媒体号码,加密的内容密钥和许可信息,并且判断许可信息是否同时反映媒体号和加密的内容密钥。 再现设备解密加密的内容密钥,并且仅在许可信息反映这两个值时才使用内容密钥来解密加密的内容。 因此,版权保护系统仅允许再现原始记录介质,并且禁止复制记录介质的再现。

    Secure device
    43.
    发明申请
    Secure device 失效
    安全设备

    公开(公告)号:US20070234074A1

    公开(公告)日:2007-10-04

    申请号:US11802860

    申请日:2007-05-25

    IPC分类号: G06F12/14

    摘要: A secure device is provided that can store programs therein, the secure device including: a low-protection level storage unit; a high-protection level storage unit; a program acquiring unit that acquires a program and corresponding additional information, the additional information used for determining a storage destination of the acquired program; an additional information analyzing unit that stores the acquired program in one of the low-protection level storage unit and the high-protection level storage unit, according to additional information; an area searching unit; a protection level judging unit; and a program storing unit.

    摘要翻译: 提供一种能够在其中存储程序的安全装置,该安全装置包括:低保护等级的存储单元; 高保护级存储单元; 程序获取单元,其获取程序和相应的附加信息,所述附加信息用于确定所获取的程序的存储目的地; 附加信息分析单元,根据附加信息将获取的程序存储在低保护等级存储单元和高保护等级存储单元之一中; 区域搜索单元; 保护等级判断单元; 和程序存储单元。

    One-way data conversion apparatus and device authentication system
    44.
    发明授权
    One-way data conversion apparatus and device authentication system 失效
    单向数据转换装置和设备认证系统

    公开(公告)号:US6049611A

    公开(公告)日:2000-04-11

    申请号:US963680

    申请日:1997-10-31

    IPC分类号: H04L9/32 G09C1/00 H04L9/00

    摘要: The verifier apparatus 50 includes a random number generation unit 51 that generates a 2n-bit random number, a separator unit 52 that separates the random number into two sets of n-bit data, a data conversion module 53 that converts one set of separated data using the other set of separated data as a key, and a comparator unit 54 that judges whether the converted result matches claimant data sent back from the claimant apparatus 60. The claimant apparatus 60 includes a separator unit 61 and a data conversion module 62 that have the same functions as the separator unit 52 and the data conversion module 53 in the verifier apparatus 50. The claimant apparatus 60 generates n-bit claimant data from the 2n-bit random number generated by the verifier apparatus 50, and sends the generated claimant data to the verifier apparatus 50.

    摘要翻译: 验证装置50包括生成2n位随机数的随机数生成单元51,将随机数分成两组n位数据的分离单元52,将一组分离数据进行转换的数据转换模块53 使用另一组分离的数据作为键,以及比较器单元54,其判断转换的结果是否与从索赔者装置60发回的索赔数据相匹配。索赔者装置60包括分离单元61和数据转换模块62, 与验证器装置50中的分离器单元52和数据转换模块53具有相同的功能。索赔装置60根据由验证器装置50生成的2n位随机数生成n位请求者数据,并发送所生成的请求者数据 到验证器装置50。

    Apparatus and method for data encryption with block selection keys and
data encryption keys
    45.
    发明授权
    Apparatus and method for data encryption with block selection keys and data encryption keys 失效
    具有块选择键和数据加密密钥的数据加密的装置和方法

    公开(公告)号:US5351299A

    公开(公告)日:1994-09-27

    申请号:US71546

    申请日:1993-06-04

    IPC分类号: H04L9/06 H04K1/04

    摘要: Disclosed is a data encryption apparatus strong to differential cryptanalysis, which is now the most influential cryptanalysis method.According to the data encryption apparatus, input data is divided into N blocks, 1 to N-1 blocks of which is selected by a first selection unit with a block selection key. Then the selected blocks of data is compressed into a single block of data in a first combination unit, and encrypted with a data encryption key in an F-function unit. A second combination unit combines the blocks of data not selected in the first selection unit with the output of the F-function unit by XOR. An output unit outputs N blocks of data arranged in the same order as the initial N blocks, in which the 1 to N-1 blocks selected in the first selection unit are outputted without any change, and the other blocks being the outputs of the second combination unit.

    摘要翻译: 公开了一种对差分密码分析具有强大的数据加密装置,现在是最有影响力的密码分析方法。 根据数据加密装置,输入数据被划分为N个块,其中1个到N-1个块由具有块选择密钥的第一选择单元选择。 然后将所选择的数据块压缩成第一组合单元中的单个数据块,并用F函数单元中的数据加密密钥进行加密。 第二组合单元通过异或将第一选择单元中未选择的数据块与F函数单元的输出相组合。 输出单元输出以与初始N个块相同的顺序排列的N个数据块,其中在第一选择单元中选择的1到N-1块被输出而没有任何改变,其他块是第二个 组合单位

    Method for generating a public key
    46.
    发明授权
    Method for generating a public key 失效
    用于生成公钥的方法

    公开(公告)号:US5199070A

    公开(公告)日:1993-03-30

    申请号:US809134

    申请日:1991-12-18

    IPC分类号: H04L9/30

    CPC分类号: H04L9/3013 H04L9/3073

    摘要: A authentic public key of the other party of user in communications is generated using the other party's user information and identification information, and a center's public information. The center doesn't know the user's secret keys, and no secret communication paths are required between the center and the users. The workload of the users is not increased even if a plurality of centers are introduced to prevent possible wrongdoing by the center.

    摘要翻译: 使用对方的用户信息和识别信息以及中心的公共信息生成通信用户的另一方的真实公钥。 中心不知道用户的密钥,中心和用户之间不需要秘密的通信路径。 即使引入了多个中心来防止可能的中心错误,用户的工作量也不会增加。

    Content distribution system, content management server, content-using device, and control method
    47.
    发明授权
    Content distribution system, content management server, content-using device, and control method 有权
    内容分发系统,内容管理服务器,内容使用设备和控制方法

    公开(公告)号:US09419864B2

    公开(公告)日:2016-08-16

    申请号:US13878851

    申请日:2012-08-22

    摘要: A content management server comprises: a first connection detection unit that detects whether or not the content management server is connected with the content-using device; a content management unit that manages the content according to a result of the detection by the first connection detection unit and holds information on how the content-using device controls the use of the content. A content-using device comprises: a second connection detection unit that detects whether or not the content-using device is connected with the content management server; a second selection unit that specifies a method for controlling the use of the content according to a result of the detection by the second connection detection unit; and a content control unit that controls the use of the content according to the method specified by the second selection unit.

    摘要翻译: 内容管理服务器包括:第一连接检测单元,其检测内容管理服务器是否与内容使用设备连接; 内容管理单元,其根据第一连接检测单元的检测结果来管理内容,并且保存关于内容使用设备如何控制内容的使用的信息。 内容使用设备包括:第二连接检测单元,其检测所述内容使用设备是否与所述内容管理服务器连接; 第二选择单元,其指定根据第二连接检测单元的检测结果来控制内容的使用的方法; 以及内容控制单元,其根据由第二选择单元指定的方法控制内容的使用。

    Monitoring system, program-executing device, monitoring program, recording medium and integrated circuit
    48.
    发明授权
    Monitoring system, program-executing device, monitoring program, recording medium and integrated circuit 有权
    监控系统,程序执行装置,监控程序,记录介质和集成电路

    公开(公告)号:US08745735B2

    公开(公告)日:2014-06-03

    申请号:US13128080

    申请日:2009-11-20

    IPC分类号: H04L29/06 G06F21/00

    CPC分类号: G06F21/57 G06F21/55

    摘要: To aim to provide a monitoring system and a program execution apparatus that are capable of maintaining the security intensity even in the case where an unauthentic install module is invalidated. Install modules included in an apparatus each monitor an install module, which is a monitoring target indicated by a monitoring pattern included therein, as to whether the install module performs malicious operations. An install module that performs malicious operations is invalidated in accordance with an instruction from an update server. The monitoring patterns are restructured by the update server such that the install modules except the invalidated install module are each monitored by at least another one of the install modules. The restructured monitoring patterns are distributed to the install modules except the invalidated install module.

    摘要翻译: 为了提供即使在不正当的安装模块被无效的情况下也能够保持安全强度的监视系统和程序执行装置。 安装在装置中的模块各自监视作为由其中包含的监视模式指示的监视目标的安装模块,关于该安装模块是否执行恶意操作。 根据更新服务器的指令,执行恶意操作的安装模块无效。 监视模式由更新服务器重构,使得除了无效的安装模块之外的安装模块各自由至少另一个安装模块监视。 重组的监控模式分发到除了无效的安装模块之外的安装模块。

    CONTENT MANAGEMENT DEVICE AND CONTENT MANAGEMENT METHOD
    49.
    发明申请
    CONTENT MANAGEMENT DEVICE AND CONTENT MANAGEMENT METHOD 有权
    内容管理设备和内容管理方法

    公开(公告)号:US20130191927A1

    公开(公告)日:2013-07-25

    申请号:US13877833

    申请日:2012-08-07

    IPC分类号: G06F21/60

    摘要: Provided is a content management device for protecting a content of a provider. A content management device 800 deletes one or more contents shared with and held by a user of another device. The content management device 800 comprises: a sharing unit 801 configured to distribute the contents to the user and thereby share the contents with the user; and a switching unit 802 configured to switch a method of the deletion to another method according to a time elapsed from the distribution.

    摘要翻译: 提供了一种用于保护提供者的内容的内容管理装置。 内容管理装置800删除由另一装置的用户共享和保持的一个或多个内容。 内容管理装置800包括:共享单元801,被配置为将内容分发给用户,从而与用户共享内容; 以及切换单元802,被配置为根据从分发经过的时间将删除的方法切换到另一种方法。

    Encryption device and encryption system
    50.
    发明授权
    Encryption device and encryption system 有权
    加密设备和加密系统

    公开(公告)号:US08484485B2

    公开(公告)日:2013-07-09

    申请号:US12936740

    申请日:2009-05-14

    摘要: An encryption apparatus prevents plaintext data from leaking even if accumulated data is analyzed, while preventing the size of encrypted data from increasing. The encryption apparatus encrypts a data piece that is smaller than a unit length and stores management information indicating a used area within an encryption area defined based on the unit length. The used area is an area already used for encryption. When encrypting a new data piece that is smaller than the unit length, the encryption apparatus generates encrypted data by adding the new data piece to an unused area within the encryption area with reference to the management information. The unused area is an area not yet used for encryption. The encryption apparatus updates the management information to include an area for the new data piece into the used area, after generating the encrypted data.

    摘要翻译: 即使分析了累积数据,加密装置也防止明文数据泄漏,同时防止加密数据的大小增加。 加密装置对小于单位长度的数据进行加密,并将指示使用区域的管理信息存储在基于单位长度定义的加密区域内。 使用区域是已经用于加密的区域。 当加密小于单位长度的新的数据段时,加密装置通过参考管理信息将新的数据段添加到加密区域内的未使用区域来生成加密数据。 未使用的区域是尚未用于加密的区域。 在生成加密数据之后,加密装置更新管理信息以将新数据段的区域包括到使用区域中。