Device authentication system which allows the authentication function to
be changed
    1.
    发明授权
    Device authentication system which allows the authentication function to be changed 失效
    允许更改认证功能的设备认证系统

    公开(公告)号:US6034618A

    公开(公告)日:2000-03-07

    申请号:US940076

    申请日:1997-09-29

    IPC分类号: H04L9/32 G06F11/00

    CPC分类号: H04L9/3271

    摘要: The decoder apparatus 90 generates a random number R1 for authenticating the optical disc drive apparatus 70 and sends it to the optical disc drive apparatus 70 as the challenge data CHA1. The optical disc drive apparatus 70 selects one out of the sixteen claimant functions stored in the claimant function unit 722 and calculates the function value fi(CHA1) which it sends to the decoder apparatus 90 as the response data RES1. The decoder apparatus 90 compares the response data RES1 with sixteen function values f1(R1) to f16(R1) that are obtained using the sixteen verification functions stored in the verification function unit 922, and authenticates the optical disc drive apparatus 70 when at least one of the function values matches the response data RES1.

    摘要翻译: 解码器装置90生成用于认证光盘驱动装置70的随机数R1,并将其发送到作为挑战数据CHA1的光盘驱动装置70。 光盘驱动装置70选择存储在权利要求函数单元722中的十六个要求函数中的一个,并将作为响应数据RES1发送给解码装置90的函数值fi(CHA1)进行计算。 解码器装置90将响应数据RES1与使用存储在验证功能单元922中的十六个验证功能获得的十六个功能值f1(R1)至f16(R1)进行比较,并且当至少一个 的功能值与响应数据RES1匹配。

    One-way data conversion apparatus and device authentication system
    2.
    发明授权
    One-way data conversion apparatus and device authentication system 失效
    单向数据转换装置和设备认证系统

    公开(公告)号:US6049611A

    公开(公告)日:2000-04-11

    申请号:US963680

    申请日:1997-10-31

    IPC分类号: H04L9/32 G09C1/00 H04L9/00

    摘要: The verifier apparatus 50 includes a random number generation unit 51 that generates a 2n-bit random number, a separator unit 52 that separates the random number into two sets of n-bit data, a data conversion module 53 that converts one set of separated data using the other set of separated data as a key, and a comparator unit 54 that judges whether the converted result matches claimant data sent back from the claimant apparatus 60. The claimant apparatus 60 includes a separator unit 61 and a data conversion module 62 that have the same functions as the separator unit 52 and the data conversion module 53 in the verifier apparatus 50. The claimant apparatus 60 generates n-bit claimant data from the 2n-bit random number generated by the verifier apparatus 50, and sends the generated claimant data to the verifier apparatus 50.

    摘要翻译: 验证装置50包括生成2n位随机数的随机数生成单元51,将随机数分成两组n位数据的分离单元52,将一组分离数据进行转换的数据转换模块53 使用另一组分离的数据作为键,以及比较器单元54,其判断转换的结果是否与从索赔者装置60发回的索赔数据相匹配。索赔者装置60包括分离单元61和数据转换模块62, 与验证器装置50中的分离器单元52和数据转换模块53具有相同的功能。索赔装置60根据由验证器装置50生成的2n位随机数生成n位请求者数据,并发送所生成的请求者数据 到验证器装置50。

    Authentication system and key registration apparatus
    4.
    发明授权
    Authentication system and key registration apparatus 失效
    认证系统和密钥登记设备

    公开(公告)号:US07296147B2

    公开(公告)日:2007-11-13

    申请号:US10454531

    申请日:2003-06-05

    IPC分类号: H04L9/00 H04K1/00 G06K9/00

    摘要: In an authentication system, a key registration apparatus receives input of an identifier unique to a second device, generates first key data from the identifier according to a predetermined key generation algorithm, and transmits the generated first key data to a first device, which receives and stores the first key data, and authenticates the second device with use of the first key data. The second device stores in advance second key data generated from the identifier according to the predetermined key generation algorithm, and is authenticated by the first device with use of the second key data. Accordingly, the first and second devices cannot be registered without using the key registration apparatus, thereby preventing communication with unregistered devices. This enables usage of content to be limited to individual usage in the home of a user, and can be realized even with devices that are not connected outside the home.

    摘要翻译: 在认证系统中,密钥注册装置接收对第二装置唯一的标识符的输入,根据预定的密钥生成算法从标识符生成第一密钥数据,并将生成的第一密钥数据发送到第一装置, 存储第一密钥数据,并使用第一密钥数据认证第二设备。 第二设备预先存储根据预定密钥生成算法从标识符生成的第二密钥数据,并且通过第二密钥数据由第一设备认证。 因此,在不使用密钥登记装置的情况下,不能登记第一和第二装置,从而防止与未登记装置的通信。 这使得内容的使用被限制在用户的家庭中的个人使用,并且即使使用不在家外的设备也可以实现。

    Digital work protection system, key management apparatus, and user apparatus
    5.
    发明授权
    Digital work protection system, key management apparatus, and user apparatus 有权
    数字工作保护系统,密钥管理装置和用户装置

    公开(公告)号:US07272229B2

    公开(公告)日:2007-09-18

    申请号:US10278082

    申请日:2002-10-23

    IPC分类号: H04L9/00

    摘要: In a system composed of a recording apparatus that records digitized content such as a movie, or a reproduction apparatus that reproduces the digitized content, and a recording medium, a media key for use in recording or reproduction is encrypted by a plurality of device keys and recorded on the recording medium. Here, the recording apparatus or the reproduction apparatus specifies the encrypted media key that it is to decrypt, from amongst the plurality of encrypted media keys. A key management apparatus records node revocation patterns assigned to nodes in a tree structure to the recording medium in a particular order, as header information of key information, together with the encrypted media keys. The recording apparatus or the reproduction apparatus specifies the encrypted media key to be decrypted, by analyzing the node revocation patterns sequentially.

    摘要翻译: 在记录诸如电影的数字化内容的记录装置或再现数字化内容的再现装置以及记录介质的系统中,用于记录或再现的媒体密钥由多个设备密钥加密, 记录在记录介质上。 这里,记录装置或再现装置从多个加密媒体密钥中指定要解密的加密媒体密钥。 密钥管理装置将分配给树结构中的节点的节点撤销模式以特定顺序记录到记录介质上,作为密钥信息的头信息以及加​​密的媒体密钥。 记录装置或再现装置通过依次分析节点撤销模式来指定要解密的加密媒体密钥。

    Secure device
    7.
    发明授权
    Secure device 失效
    安全设备

    公开(公告)号:US07739519B2

    公开(公告)日:2010-06-15

    申请号:US11802860

    申请日:2007-05-25

    IPC分类号: H04L9/32 G06F11/30 H04L9/00

    摘要: A secure device is provided that can store programs therein, the secure device including: a low-protection level storage unit; a high-protection level storage unit; a program acquiring unit that acquires a program and corresponding additional information, the additional information used for determining a storage destination of the acquired program; an additional information analyzing unit that stores the acquired program in one of the low-protection level storage unit and the high-protection level storage unit, according to additional information; an area searching unit; a protection level judging unit; and a program storing unit.

    摘要翻译: 提供一种能够在其中存储程序的安全装置,该安全装置包括:低保护等级的存储单元; 高保护级存储单元; 程序获取单元,其获取程序和相应的附加信息,所述附加信息用于确定所获取的程序的存储目的地; 附加信息分析单元,根据附加信息将获取的程序存储在低保护等级存储单元和高保护等级存储单元之一中; 区域搜索单元; 保护等级判断单元; 和程序存储单元。

    DATA PROTECTION SYSTEM THAT PROTECTS DATA BY ENCRYPTING THE DATA

    公开(公告)号:US20100034388A1

    公开(公告)日:2010-02-11

    申请号:US12104165

    申请日:2008-04-16

    IPC分类号: H04L9/00 G06F7/04

    摘要: A data protection system is provided that reduces, to a degree, the amount of encrypted data that is distributed to a plurality of terminals. In the data protection system a terminal whose decryption keys are exposed by a dishonest party is made to be unable to decrypt the data correctly, while other terminals are able to decrypt the data correctly.The data protection system includes a plurality of terminals, and an encryption device that encrypts distribution data distributed to each terminal. Each terminal is corresponded with one node on a lowest level of a 4-ary tree structure or the like having a plurality of hierarchies. The data protection system, for each node in the tree structure, excluding those on the lowest level, determines a plurality of combination patterns that include combinations of two or more of all four nodes that are reached one level below the node, decides an individual decryption key for each determined combination pattern, and decides an individual decryption key for each node on the lowest level. Further, the data protection system has each terminal store all decryption keys decided for the nodes on the path from the node on the lowest level that corresponds to the terminal through to the node on the highest level. The data protection system prescribes nodes that are reached from the node on the lowest level that corresponds to the terminal through to the node on the highest level that correspond to a terminal that has been dishonestly analyzed as invalid nodes. For invalid nodes, other than invalid nodes on the lowest level, the data protection system designates an encryption key that corresponds to the decryption key decided in correspondence with the combination pattern that combines all nodes, excluding invalid nodes, of the four nodes that are reached one level below the node, and has the encryption device encrypt distribution data that uses each of the designated encryption keys.

    Deactivation system
    9.
    发明授权
    Deactivation system 有权
    停用系统

    公开(公告)号:US07503066B2

    公开(公告)日:2009-03-10

    申请号:US10413523

    申请日:2003-04-15

    IPC分类号: G06F12/00

    摘要: A deactivation method is for a system including a communication terminal, a secure device, and a management apparatus. An identification number and communication identification code are notified to the management apparatus while the secure device is attached to the communication terminal. The management apparatus holds the identification number and the communication identification code by correlating them, acquires an identification number of a secure device to be deactivated, when instructed to deactivate the secure device by an authentic owner of a right to use the secure device, extracts the communication identification code in accordance with the identification number, and transmits the deactivation authentication code to an apparatus identified by the extracted communication identification code. If the communication terminal receives the deactivation authentication code while the secure device is attached to it, the secure device is deactivated.

    摘要翻译: 停用方法是用于包括通信终端,安全装置和管理装置的系统。 当安全装置附接到通信终端时,将识别号码和通信识别码通知给管理装置。 管理装置通过将识别号码和通信识别码相关联,取得要停用的安全装置的识别号码,当被指示使用安全装置的权利的真实所有者停止安全装置时,提取 通信识别码,并将去激活认证码发送到由所提取的通信识别码识别的装置。 如果通信终端在安全设备附加到其时接收到去激活认证码,则安全设备被去激活。