Data transmitting system and method, drive unit, access method, data recording medium, recording medium producing apparatus and method
    61.
    发明申请
    Data transmitting system and method, drive unit, access method, data recording medium, recording medium producing apparatus and method 有权
    数据传输系统和方法,驱动单元,访问方法,数据记录介质,记录介质的制造装置和方法

    公开(公告)号:US20080072040A1

    公开(公告)日:2008-03-20

    申请号:US11797600

    申请日:2007-05-04

    IPC分类号: H04L9/32 H04L9/30

    摘要: A security module is provided in a data recording medium, data to be written to the data recording medium is encrypted with an content key different from one data to another, and the content key is safely stored in the security module. Also, the security module makes a mutual authentication using the public-key encryption technology with a drive unit to check that the counterpart is an authorized (licensed) unit, and then gives the content key to the counterpart, thereby preventing data from being leaked to any illegal (unlicensed) unit. Thus, it is possible to prevent copyrighted data such as movie, music, etc. from being copied illegally (against the wish of the copyrighter of the data).

    摘要翻译: 在数据记录介质中提供安全模块,用不同于一个数据的内容密钥对要写入数据记录介质的数据进行加密,并将内容密钥安全地存储在安全模块中。 此外,安全模块使用具有驱动单元的公共密钥加密技术进行相互认证,以检查对方是授权(许可)单元,然后向对方发送内容密钥,从而防止数据泄漏到 任何非法(无牌)单位。 因此,可以防止诸如电影,音乐等的受版权保护的数据被非法复制(相对于数据的复制者的愿望)。

    Information recording device, information playback device, information recording method, information playback method, and information recording medium and program providing medium used therewith
    62.
    发明授权
    Information recording device, information playback device, information recording method, information playback method, and information recording medium and program providing medium used therewith 失效
    信息记录装置,信息重放装置,信息记录方法,信息重放方法以及与其一起使用的信息记录介质和程序提供介质

    公开(公告)号:US07319752B2

    公开(公告)日:2008-01-15

    申请号:US09947097

    申请日:2001-09-05

    IPC分类号: H04L9/14

    摘要: An information recording/playback device stores beforehand, on a recording medium, secret information in which a writing/reading method thereof cannot be analyzed and which can be read only by a special reading method. The secret information is applied to a key for content encryption or decryption when performing recording or playback of contents on the recording medium, such as music data and image data. The secret information is, for example, a stamper ID. By using the stamper ID as secret information, and a master key and a media key which are distributed in a tree-structure key-distribution system, a content-cryptosystem key is generated. Accordingly, each content is allowed to be used in only an appropriate device in which the special reading method for the secret information can be executed and to which the key is distributed by the tree-structure key-distribution system.

    摘要翻译: 信息记录/重放装置预先在记录介质上存储其中不能分析其书写/读取方法的秘密信息,并且只能通过专门的读取方法来读取该秘密信息。 当在诸如音乐数据和图像数据的记录介质上执行内容的记录或回放时,秘密信息被应用于内容加密或解密的密钥。 秘密信息例如是压模ID。 通过使用压模ID作为秘密信息,以及分配在树结构密钥分发系统中的主密钥和媒体密钥,生成内容密码系统密钥。 因此,允许每个内容仅在可以执行用于秘密信息的特殊读取方法的适当的设备中使用,并且由树结构密钥分发系统将密钥分发给密钥。

    Information processing system and method using encryption key block
    63.
    发明申请
    Information processing system and method using encryption key block 失效
    信息处理系统和方法采用加密密钥块

    公开(公告)号:US20070263875A1

    公开(公告)日:2007-11-15

    申请号:US11879639

    申请日:2007-07-18

    IPC分类号: H04L9/00

    摘要: An information processing system and method using an encryption key block sets sub-trees classified based on data processing ability of the devices (capability) in a key tree in which respective keys are corresponded to a root, nodes and leaves of a tree in which a plurality of devices are constituted as the leaves, generates a sub-enabling key block which is effective for an entity in a managing subject of each sub-tree (entity), and generates an enabling key block decodable only by the entities having common capability. Also, an information processing system and method using an encryption key block manages a partial tree of a key tree (sub-tree), generates a sub-enabling key block based only on a key set corresponding to nodes or leaves included in the sub-tree, and generates an enabling key block decodable only by selected entities by using the sub-enabling key block. Thus, it is possible to generate and distribute an enabling key block corresponding to data processing ability of a device and to manage devices by dividing a hierarchical key tree structure.

    摘要翻译: 使用加密密钥块的信息处理系统和方法基于密钥树中的设备(能力)的数据处理能力分类的子树,其中各个密钥对应于树的根,节点和树叶,其中 多个设备被构成为叶子,生成对于每个子树(实体)的管理对象中的实体有效的子启用密钥块,并且生成仅能够由具有共同能力的实体解码的启用密钥块。 此外,使用加密密钥块的信息处理系统和方法管理密钥树(子树)的部分树,仅基于与包括在子树中的节点或叶子相对应的密钥集来生成子启用密钥块, 并且通过使用子启用密钥块来生成仅由选择的实体可解码的启用密钥块。 因此,可以生成并分配与设备的数据处理能力相对应的启用密钥块,并且通过划分分层密钥树结构来管理设备。

    Information recording/playback apparatus and method
    64.
    发明授权
    Information recording/playback apparatus and method 有权
    信息记录/播放装置和方法

    公开(公告)号:US07225339B2

    公开(公告)日:2007-05-29

    申请号:US09980272

    申请日:2001-04-05

    IPC分类号: H04L9/00

    摘要: In a tree-structural key distribution system, renewed data of a master key and medium key are sent along with a key renewal block (KRB). KRB is such that each of devices included as leaves of a tree structure has a leaf key and restricted node key. A specific KRB can be generated for a group identified by a specific node and distributed to the group to restrict a device for which the key can be renewed. Any device not belonging to the group cannot decrypt the key, whereby the security of key distribution can be assured. Especially in a system using a generation-managed master key, a master key renewed with KRB can be distributed.

    摘要翻译: 在树结构密钥分配系统中,主密钥和中密钥的更新数据与密钥更新块(KRB)一起发送。 KRB使得作为树结构的叶片包括的每个设备具有叶密钥和受限节点密钥。 可以为由特定节点识别的组生成特定的KRB,并且分配给组以限制可以更新密钥的设备。 任何不属于该组的设备都不能解密该密钥,从而可以确保密钥分配的安全性。 特别是在使用生成管理的主密钥的系统中,可以分配用KRB更新的主密钥。

    Information processing apparatus, information processing method, information processing system and recording medium
    66.
    发明授权
    Information processing apparatus, information processing method, information processing system and recording medium 有权
    信息处理装置,信息处理方法,信息处理系统和记录介质

    公开(公告)号:US07065214B2

    公开(公告)日:2006-06-20

    申请号:US10195022

    申请日:2002-07-12

    IPC分类号: H04L9/00

    摘要: An information processing apparatus and an information processing method capable of preventing information from being copied illegally. where a hash function and a service key are stored in advance in an EEPROM of a DVD player serving as a source. In an BEPROM of a personal computer (PC) serving as a sink, on the other hand, its ID and a license key are stored beforehand. The DVD player requests the PC to transmit the ID. The DVD player then applies the hash function to data resulting from concatenation of the lID with the service key to generate a license key (=hash (ID ∥service_key)). Subsequently, the DVD player generates a source side common session key and encrypts the session key by using the generated license key. Then, the DVD player transmits the encrypted source side common session key to the PC. The PC decrypts the encrypted source side common session key by using the license key stored in its EEPROM to produce a sink side common session key which has a value equal to that of the source side common session key.

    摘要翻译: 一种能够防止信息被非法复制的信息处理装置和信息处理方法。 其中散列函数和服务密钥预先存储在用作源的DVD播放器的EEPROM中。 另一方面,在用作接收器的个人计算机(PC)的BEPROM中,其ID和许可证密钥被预先存储。 DVD播放器请求PC传送ID。 然后,DVD播放器将散列函数应用于由ID连接到服务密钥产生的数据,以生成许可密钥(= hash(ID∥service_key))。 随后,DVD播放器生成源侧公共对话密钥,并通过使用所生成的许可证密钥来加密会话密钥。 然后,DVD播放器将加密的源侧公共会话密钥发送到PC。 PC通过使用存储在其EEPROM中的许可证密钥来解密加密的源侧公共会话密钥,以产生具有等于源侧公共会话密钥的值的宿侧公共会话密钥。

    Information processing system and method
    67.
    发明授权
    Information processing system and method 失效
    信息处理系统和方法

    公开(公告)号:US06911974B2

    公开(公告)日:2005-06-28

    申请号:US10204514

    申请日:2001-12-21

    摘要: An information processing system and method are disclosed in which information processing is performed in a highly efficient manner using an enabling key block (EKB) on the basis of a tree structure including category subtrees. A key tree is formed so as to include a plurality of subtrees serving as category trees categorized in accordance with categories and managed by category entities. An EKB including data produced by selecting a path in a tree and encrypting a higher-level key in the selected path using a lower-level key in the selected path. The resultant EKB is provided to a device. Distribution of EKB's is managed on the basis of an EKB type definition list representing the correspondence between an EKB type identifier and one or more identification data identifying one or more category trees that can process an EKB of an EKB type specified by the EKB type identifier.

    摘要翻译: 公开了一种信息处理系统和方法,其中使用基于包括类别子树的树结构的启用密钥块(EKB)以高效的方式执行信息处理。 形成关键树,以便包括用作根据类别分类并由类别实体管理的类别树的多个子树。 EKB包括通过选择树中的路径并使用所选路径中的较低级别的密钥加密所选路径中的较高级的密钥而产生的数据。 所得到的EKB被提供给设备。 基于表示EKB类型标识符与识别可以处理由EKB类型标识符指定的EKB类型的EKB的一个或多个类别树的一个或多个标识数据之间的对应关系的EKB类型定义列表来管理EKB的分发。

    Content processing system
    68.
    发明授权
    Content processing system 失效
    内容处理系统

    公开(公告)号:US06834346B1

    公开(公告)日:2004-12-21

    申请号:US09509583

    申请日:2000-03-28

    IPC分类号: H04L916

    摘要: A first information processing unit 100 stores identification information into a storage module 152, stores an encrypted contents signal into a mass storage unit 180, and supplies the encrypted contents signal and identification information to a second information processing unit 200 through a communication section 110. In a receiving unit 170 of the first information processing unit 100, log information generated by a purchase processing module 153 is stored into the storage module 152 every time the contents key is decoded, and the log information is transmitted at predetermined timing to a key management center 30 through the transmission section 110. The second information processing unit 200 receives the encrypted contents signal and the identification information through a communication section 210, and causes a contents processing section 260 to decode the encrypted contents signal and to append the identification information thereto.

    摘要翻译: 第一信息处理单元100将识别信息存储到存储模块152中,将加密内容信号存储到大容量存储单元180中,并通过通信部110将加密的内容信号和识别信息提供给第二信息处理单元200.在 第一信息处理单元100的接收单元170,每当内容密钥被解码时,由购买处理模块153产生的日志信息被存储到存储模块152中,并且将日志信息以预定的定时发送到密钥管理中心 第二信息处理单元200通过通信部件210接收加密的内容信号和识别信息,并使内容处理部分260对加密的内容信号进行解码并附加识别信息。

    Data transmission apparatus and method, data receiving apparatus and method, and data transmitting/receiving system and method
    69.
    发明授权
    Data transmission apparatus and method, data receiving apparatus and method, and data transmitting/receiving system and method 失效
    数据传输装置和方法,数据接收装置和方法以及数据发送/接收系统和方法

    公开(公告)号:US06539094B1

    公开(公告)日:2003-03-25

    申请号:US09059762

    申请日:1998-04-14

    IPC分类号: H04L900

    摘要: Data to be transmitted via a serial bus in conformity with the IEEE 1394 protocol are ciphered by a ciphering/deciphering circuit, and headers are attached thereto by a header sync detecting/generating circuit. And after further attachment of CRC code by a CRC detector/generator, the data are packetized into isochronous packets of an isochronous mode by a transmission/reception switching circuit, whereby transmission of the data can be performed with enhanced security. Out of cipher keys employed, a session key invariable in each session of the data is transmitted in each packet of an asynchronous mode, and a time variable updated in each session is transmitted in each packet of an isochronous mode. And the ciphered data obtained by depacketizing the packets of the isochronous mode are deciphered, so that the data transmitted with security can be deciphered exactly, and thus illegal use of the data can be prevented with certainty.

    摘要翻译: 通过符合IEEE 1394协议的串行总线发送的数据由加密/解密电路加密,并通过报头同步检测/生成电路附加标题。 并且在通过CRC检测器/发生器进一步附加CRC码之后,通过发送/接收切换电路将数据分组成同步模式的等时分组,从而可以以更高的安全性进行数据的传输。 在采用的密码密钥之外,在每个异步模式的数据包中发送数据的每个会话中不变的会话密钥,并且在每个会话中更新的时间变量在等时模式的每个分组中被发送。 并且通过对同步模式的分组进行解包获得的加密数据被解密,从而可以准确地解密传输的数据,从而可以确定地防止数据的非法使用。

    DATA TRANSMITTING SYSTEM AND METHOD, DRIVE UNIT, ACCESS METHOD, DATA RECORDING MEDIUM, RECORDING MEDIUM PRODUCING APPARATUS AND METHOD
    70.
    发明申请
    DATA TRANSMITTING SYSTEM AND METHOD, DRIVE UNIT, ACCESS METHOD, DATA RECORDING MEDIUM, RECORDING MEDIUM PRODUCING APPARATUS AND METHOD 有权
    数据发送系统和方法,驱动单元,访问方法,数据记录介质,记录介质生产设备和方法

    公开(公告)号:US20100251357A1

    公开(公告)日:2010-09-30

    申请号:US12794568

    申请日:2010-06-04

    IPC分类号: G06F12/14

    摘要: A security module is provided in a data recording medium, data to be written to the data recording medium is encrypted with an content key different from one data to another, and the content key is safely stored in the security module. Also, the security module makes a mutual authentication using the public-key encryption technology with a drive unit to check that the counterpart is an authorized (licensed) unit, and then gives the content key to the counterpart, thereby preventing data from being leaked to any illegal (unlicensed) unit. Thus, it is possible to prevent copyrighted data such as movie, music, etc. from being copied illegally (against the wish of the copyrighter of the data).

    摘要翻译: 在数据记录介质中提供安全模块,用不同于一个数据的内容密钥对要写入数据记录介质的数据进行加密,并将内容密钥安全地存储在安全模块中。 此外,安全模块使用具有驱动单元的公共密钥加密技术进行相互认证,以检查对方是授权(许可)单元,然后向对方发送内容密钥,从而防止数据泄漏到 任何非法(无牌)单位。 因此,可以防止诸如电影,音乐等的受版权保护的数据被非法复制(相对于数据的复制者的愿望)。