Record Carrier with Copy Protection Means
    2.
    发明申请
    Record Carrier with Copy Protection Means 审中-公开
    记录载体与复制保护手段

    公开(公告)号:US20080291801A1

    公开(公告)日:2008-11-27

    申请号:US12095136

    申请日:2006-10-06

    IPC分类号: G11B5/58

    摘要: In summary, ROM marks (such as wobbles, lateral deviations in the spiral with lands and pits in an optical disc) are used on optical media to ensure consumer-grade copying devices cannot duplicate original media. An additional level of security is that the detection of the side channel information requires knowledge of a certain secret, which must be hidden well in authorized players. If the secret leaks, a professional pirate will be able to detect the ROM mark and duplicate the original medium with the side channel information intact. The present invention proposes that instead of a single ROM mark, many ROM marks are applied to a disc. Further, devices are divided into groups, and each group has the capability to only detect one mark from the group. This way, if a secret is obtained from a device, the disc can be duplicated, but only a limited number of devices will be able to use this disc. Creating a disc that can be played in any device requires the hacking of one device from every group.

    摘要翻译: 总而言之,在光学介质上使用ROM标记(例如摆动,具有光栅的螺旋和螺旋的横向偏差),以确保消费级复印装置不能复制原始介质。 额外的安全级别是,检测侧信道信息需要知道某个秘密,这必须在授权的播放器中很好地隐藏。 如果秘密泄漏,专业海盗将能够检测到ROM标记,并复制原始媒体,侧边信息完整无缺。 本发明提出,代替单个ROM标记,将许多ROM标记应用于盘。 此外,设备被分成组,并且每个组具有仅从组中检测到一个标记的能力。 这样,如果从设备获得秘密,则可以复制光盘,但是只有有限数量的设备将能够使用该光盘。 创建可以在任何设备中播放的光盘需要从每个组中窃取一个设备。

    Processing copy protection signals
    3.
    发明授权
    Processing copy protection signals 失效
    处理复制保护信号

    公开(公告)号:US07454621B2

    公开(公告)日:2008-11-18

    申请号:US10257203

    申请日:2002-02-01

    IPC分类号: G06F21/00 G06F21/22

    摘要: The invention relates to a method and an arrangement for recording an information signal with first copy protection information to a storage medium using recording means, the recording being performed according to first copy rules identified by the first copy protection information. The method comprises the steps of detecting said first copy protection information identifying said first copy rules, recording at least second copy protection information according to said detected first copy rules, said first and at least second copy protection information identifying a legality message to be interpreted by reading means, the at least second copy protection information changing within a predefined time interval after the change in said detected first copy rules according to an interpreting rule.

    摘要翻译: 本发明涉及一种使用记录装置将具有第一复制保护信息的信息信号记录到存储介质的方法和装置,该记录是根据由第一拷贝保护信息识别的第一拷贝规则进行的。 该方法包括以下步骤:检测识别所述第一复制规则的所述第一复制保护信息,根据所述检测到的第一复制规则记录至少第二复制保护信息,所述第一和至少第二复制保护信息标识要被解释的合法性消息 所述至少第二复制保护信息在所述检测到的第一复制规则根据解释规则改变之后的预定时间间隔内改变。

    DEVICE AND METHOD FOR KEY BLOCK BASED AUTHENTICATION
    4.
    发明申请
    DEVICE AND METHOD FOR KEY BLOCK BASED AUTHENTICATION 审中-公开
    基于密钥块验证的设备和方法

    公开(公告)号:US20100161972A1

    公开(公告)日:2010-06-24

    申请号:US11993262

    申请日:2006-06-26

    IPC分类号: H04L29/06

    摘要: The invention relates to a device (250) and a method for key block based authentication. In order to overcome the problems of known devices and method for authentication and to allow for an effective key block and/or application revocation wherein it is ensured that valid and new revocation information reaches said device and is used for authentication, a device (250) for a key block based authentication is proposed comprising authentication means (252) for authenticating between said device (250) having revocation information (254) and an application unit to be authenticated having a key block (AKB) by means of said revocation information (254) and said key block (AKB), and internal trigger means (256) for triggering a process of renewing of said revocation information (254).

    摘要翻译: 本发明涉及一种用于基于密钥块的认证的设备(250)和方法。 为了克服已知设备的问题和用于认证的方法,并且允许有效的密钥块和/或应用撤销,其中确保有效和新的撤销信息到达所述设备并用于认证,设备(250) 提出了一种基于密钥块的认证,包括认证装置(252),用于通过所述撤销信息(254)在具有撤销信息的所述设备(250)和具有密钥块(AKB)的待认证的应用单元之间进行认证 )和所述密钥块(AKB)以及用于触发更新所述撤销信息的过程的内部触发装置(256)。

    CONTROLLING DISTRIBUTION AND USE OF DIGITAL WORKS
    5.
    发明申请
    CONTROLLING DISTRIBUTION AND USE OF DIGITAL WORKS 审中-公开
    控制分布和使用数字工作

    公开(公告)号:US20090276635A1

    公开(公告)日:2009-11-05

    申请号:US11721060

    申请日:2005-12-07

    IPC分类号: G06F21/24 G06F21/00

    摘要: In order to efficiently prevent the save-and-restore attack on usage rights associated with digital work, these usage rights are protected by a hidden channel. In order to make it a difficult or expensive to manipulate the hidden channel, a device is proposed comprising: writing means (34) for writing on a record carrier (20) said digital work (DW) and attached usage right information (22) defining one or more conditions to be satisfied in order for the usage right to be exercised,—fingerprint extraction means (23) for deriving fingerprint data (24) from physically uncontrollable, changeable non-uniformities on said record carrier (20), and authentication means (25) for generating authentication data (26) from said fingerprint data (24) and said usage right information (22), said authentication data being provided for authenticating said usage right information, said writing means (34) being adapted for writing said authentication data (25) on said record carrier (20).

    摘要翻译: 为了有效地防止与数字作品相关的使用权的保存和恢复攻击,这些使用权利被隐藏的信道保护。 为了使操作隐藏通道变得困难或昂贵,提出了一种设备,包括:写入装置(34),用于在记录载体(20)上写入所述数字作业(DW)和附加的使用权信息(22),其定义 为了使用权被行使而要满足的一个或多个条件, - 指纹提取装置(23),用于从所述记录载体(20)上的物理上不可控制的,可变的非均匀性导出指纹数据(24);以及认证装置 (25),用于从所述指纹数据(24)和所述使用权信息(22)生成认证数据(26),所述认证数据被提供用于认证所述使用权信息,所述写入装置(34)适于写入所述认证 所述记录载体(20)上的数据(25)。

    Conditional access
    6.
    发明授权
    Conditional access 失效
    有条件访问

    公开(公告)号:US07403618B2

    公开(公告)日:2008-07-22

    申请号:US10024739

    申请日:2001-12-19

    IPC分类号: H04N9/67 H04N7/16 H04N5/275

    摘要: A transmitter provides receivers conditional access to data transmitted via a network. A content encryptor is used to encrypt the data under control of a same authorization key before it is transmitted to all receivers. The transmitter has a storage with a plurality of device keys. A further encryptor is used for producing a key block with a plurality of entries, where each entry is associated with a respective one of the device keys. At least some of the entries contain a representation of the authorization key encrypted with the associated device key. The transmitter transmits the same key block to all receivers.The receiver has a subset of the device keys. A first decryptor is used to retrieve the authorization key by decrypting at least one entry of the key block that is associated with one of the device keys of the receiver. A second decryptor is used for decrypting the data under control of the authorization key.

    摘要翻译: 发射机提供接收机对通过网络传输的数据的条件访问。 内容加密器用于在相同授权密钥的控制下将数据加密到所有接收者之前。 发射机具有具有多个设备密钥的存储器。 另一加密器用于产生具有多个条目的密钥块,其中每个条目与相应的一个设备密钥相关联。 至少一些条目包含用关联的设备密钥加密的授权密钥的表示。 发射机向所有接收机发送相同的密钥块。 接收机具有设备密钥的子集。 第一解密器用于通过解密与接收器的设备密钥之一相关联的密钥块的至少一个条目来检索授权密钥。 第二解密器用于在授权密钥的控制下解密数据。

    Secure Host Interface
    10.
    发明申请

    公开(公告)号:US20080189794A1

    公开(公告)日:2008-08-07

    申请号:US11814010

    申请日:2006-01-13

    IPC分类号: G06F21/00

    摘要: The present invention relates to a digital rights management system (40) for controlling access rights to copy protected content comprising an application unit (1, 21, 41) and a drive unit (3, 23, 43), to an application unit (1, 21, 41), to a drive unit (3, 23, 43) and to a corresponding digital rights management method. In order to allow an increased security in the management of digital rights, wherein in particular a “filter-driver”-hack is made impossible or is at least substantially complicated and a reliable confirmation about a command given in respect of digital rights and its execution, a digital rights management system (40) is proposed wherein said application unit (1, 21, 41) comprises a key storage unit (45) for storing a bus key (KB), a request generation unit (47) for generating a request (7, 27) to be carried out by said drive unit including a message regarding said access rights and a challenge (RX), a communication unit (51) for transmitting said request (7, 27) and for receiving a response (13, 33) to said request (7, 27) from said drive unit (3, 23, 43), a response verification unit (49) for verifying a link between said request (7, 27) and said response (13, 33) by decoding said response (13, 33) using said bus key (KB) and by checking for the presence of an indication of said challenge (RX) in said response (13, 33) and said drive unit (3, 23, 43) comprises a key storage unit (55) for storing a bus key (KB), a communication unit (51) for receiving a request (7, 27) including a message regarding said access rights and a challenge (RX) from said application unit (1, 21, 41) and for transmitting a response (13, 33) to said request (1, 21, 41), a request processing unit (57) for verifying said request (7, 27) and processing said message, a response generation unit (59) for generating said response (13, 33) including an indication of said challenge (RX) and a reply to said message, wherein said indication of said challenge (RX) and said reply are cryptographically linked by means of said bus key (KB) and wherein indication of said challenge (RX) in said response (13, 33) indicates that said request has been carried out.