Data management system
Abstract
The present invention provides a system to ensure security of data in a computer network system. A center certifies a public-key of user of the system and distributes a secret-key. A first system comprises the center in a network, an information provider and a plurality of users. The center identifies utilization status by requests of the secret-key. The data is encrypted by the secret-key and is stored and transferred, while the data to be stored and transferred is encrypted by a secret-key different from the secret-key of the transferred data. An original data label is added to the original data, and an edit label is added to the edited data, and the center does not store the data and stores only the original data label and the edit label. A second system comprises a center and an information provider in a network, and a plurality of users utilizing the network. The center stores the original data and editing scenario, and also the original data label, user label and edit label. The data is not transferred between the users, but data label encrypted by the public-key is transferred. In electronic commerce system, every data is distributed through a mediator in the network, data which is transferred from a maker to a user is encrypted by a secret-key for encryption, and data which is transferred from the user to the maker is encrypted by a secret-key for re-encryption.
Claims
exact text as granted — not AI-modifiedI claim:
1 . A system for managing digital data to be transferred from an owner of data to a user of data via a communication network, whereby:
secret-key, public-key, private-key, owner label, user label and data label are used in the data management system; a data management center is linked to a public-key storage and a secret-key generator and is arranged on said communication network; said data management center certifies public-keys of said owner and said user, and stores said owner label, said user label and said data label; said owner presents said owner label and data label, and requests a secret-key for data encryption to said data management center; said data management center prepares a data label fingerprint from said data label, and distributes secret-key for encryption which is encrypted by using said public-key of owner together with said data label fingerprint, to said owner; said owner encrypts the data using said secret-key which is decrypted by using private-key of said owner, and transfers said encrypted data, said data label and said data label fingerprint to a first user; said first user presents user label of said first user, said data label and said data label fingerprint, and requests a secret-key for decrypting said encrypted data and a secret-key for re-encrypting said data which is decrypted, to said data management center; said data management center confirms validity of said data label by said data label fingerprint, registers said user label of first user, and distributes said secret-key for decrypting encrypted data and said secret-key for re-encrypting decrypted data, both of which are encypted by using the public-key of said first user to said first user; and said first user decrypts said secret-key for decryption and said secret-key for re-encryption by using the private-key of said first user, decrypts and uses the encrypted data using said secret-key for decryption, encrypts the decrypted data using said secret-key for re-encryption to be stored and copied, and transfers the encrypted data together with said data label, data label fingerprint and said user label of first user to the next user.
2 . A data management system according to claim 1 , wherein a copyright is registered by presenting said owner label and said data label to said data management center by said owner of data.
3 . A data management system according to claim 1 , wherein said digital data is edited by the user, and the editing scenario of said digital data is added to said data label.
4 . A data management system according to claim 3 , wherein a copyright is registered by presenting the user label of said user and data label having said editing content of said digital data to said data manaement center by said user.
5 . A data management system according to claim 1 , wherein there are a plurality of said digital data.
6 . A data management system according to claim 1 wherein digital signature is performed on said data label.
7 . A data management system according to claim 1 wherein charging a fee is performed by presenting the user label of said user and said data label to said data manaement center by said user.
8 . A data management system according to claim 7 , wherein the charging a fee is performed by metering post-payment method based on use results.
9 . A data management system according to claim 8 , wherein the metering data based on use results is stored in said data management center.
10 . A data management system according to claim 8 , wherein the metering data based on use results is stored in a device of said user.
11 . A data management system according to claim 7 , wherein the charging a fee is performed by prepayment method.
12 . A data management system according to claim 11 , wherein the prepayment data is stored in said data management center.
13 . A data management system according to claim 11 , wherein the prepayment data is stored in a device of said user.
14 . A data management system according to claim 1 wherein said digital data has general file structure and data body thereof only is encrypted.
15 . A data management system according to claim 14 , wherein a part of said data body is encrypted.
16 . A data management system according to claim 15 , wherein the part of said data body with encrypted is repeatedly arranged in said data body.
17 . A data management system according to claim 15 , wherein a plurality of parts of said data body with encrypted is intermittently arranged in said data body.
18 . A data management system according to claim 1 wherein said digital data has general file structure, and data header and data body thereof are encrypted.
19 . A data management system according to claim 18 , wherein a part of said data header and entire part of said data body are encrypted.
20 . A data management system according to claim 18 , wherein a part of said data header and a part of said data body are encrypted respectively.
21 . A data management system according to claim 1 wherein said digital data has general file structure and data header thereof only is encrypted.
22 . A data management system according to claim 21 , wherein entire part of said data header is encrypted.
23 . A data management system according to claim 21 , wherein a part of said data header only is encrypted.
24 . A data management system according to claim 1 wherein said digital data has general file structure, and only label is encrypted.
25 . A data management system according to claim 24 , wherein a part of said label only is encrypted.
26 . A data management system according to claim 1 wherein said digital data has object-formed file structure, and only method is encrypted.
27 . A system for managing digital data to be transferred from an owner of data to a user of data via broadcast, a communication network or data recording medium, whereby:
public-key, private-key, user label and data label are used in the data management system; a data management center and the owner are linked to a public-key storage, and are arranged on said communication network; said data management center certifies public-keys of said owner and said user and stores said user label and said data label; a first user obtains said digital data and daid data label from said communication network by presenting said user label to use said digital data, which is not stored in a device each of said user after using said digital data.
28 . A data management system according to claim 27 , wherein said digital data is not stored in the device of said user by deletion of said digital data.
29 . A data management system according to claim 27 , wherein said digital data is not stored in the device of said user by turning said digital data to one-way hash value.
30 . A data management system according to claim 27 , wherein said data management center is further linked to secret-key generator, and said digital data is encrypted by using a secret-key and stored in the device of said user.
31 . A data management system according to claim 27 wherein said ditigal data is edited, and edit label is obtained by adding editing scenario of said digital data to said data label.
32 . A data management system according to claim 31 , wherein said edit label is only transferred to next user.
33 . A data management system according to claim 32 , wherein said edit label is encrypted by using public-key of said next user, and is transferred to said next user;
said next user decrypts the encrypted edit label by using private-key of said next user and prensents decrypted said edit label to said data management center; said data management center transfers the ditital data based on said edit label to said next user; said next user uses and edits said digital data by editing scenario of said edit label.
34 . A data management system according to claim 32 , wherein said first user transfers said edit label to said next user;
said next user presents said edit label to said data management center; said data management center said digital data based on said edit label to said next user; said next user uses and edits said digital data by editing scenario of said edit label.
35 . A data management system according to claim 34 , wherein said first user performs digital signature to said edit label by using private-key of said first user.
36 . A data management system according to claim 27 wherein there are a plurality of said digital data.
37 . A data management system according to claim 27 wherein charging a fee is performed by presenting said user label and said data label to said data management center by said user.
38 . A data management system according to claim 37 , wherein the charging a fee is performed by metering post-payment method based on use results.
39 . A data management system according to claim 38 , wherein the metering data based on use results is stored in said data management center.
40 . A data management system according to claim 38 , wherein the metering data based on use results is stored in a device of said user.
41 . A data management system according to claim 37 , wherein the charging fee is performed by prepayment method.
42 . A data management system according to claim 41 , wherein the prepayment data is stored in said data management center.
43 . A data management system according to claim 41 , wherein the prepayment data is stored in a device of said user.
44 . A data management system according to claim 27 wherein said digital data has general file structure and data body thereof only is encrypted.
45 . A data management system according to claim 44 , wherein a part of said data body is encrypted.
46 . A data management system according to claim 45 , wherein the part of said data body with encrypted is repeatedly arranged in said data body.
47 . A data management system according to claim 45 , wherein a plurality of parts of said data body with encrypted is intermittently arranged in said data body.
48 . A data management system according to claim 27 wherein said digital data has general file structure, and data header and data body thereof are encrypted.
49 . A data management system according to claim 48 , wherein a part of said data header and entire part of said data body are encrypted.
50 . A data management system according to claim 48 , wherein a part of said data header and a part of said data body are encrypted respectively.
51 . A data management system according to claim 27 wherein said digital data has general file structure and data header thereof only is encrypted.
52 . A data management system according to claim 51 , wherein entire part of said data header is encrypted.
53 . A data management system according to claim 51 , wherein a part of said data header only is encrypted.
54 . A data management system according to claim 27 wherein said digital data has general file structure, and only label is encrypted.
55 . A data management system according to claim 54 , wherein a part of said label only is encrypted.
56 . A data management system according to claim 27 wherein said digital data has object-formed file structure, and only method is encrypted.
57 . A system for electronic commerce between maker and user via mediator, whereby:
secret-key, public-key and private-key are used in the electronic commerce system; said mediator is linked to a public-key storage and a secret-key generator and is arranged on a communication network; said user requests electronic commerce data to said mediator; said mediator transfers the request of said electronic commerce data together with secret-key for encryption, which is encrypted by using public-key of said maker, to said maker; said maker decrypts encrypted secret-key for encryption by using private-key of said maker, and encrypts said electronic commerce data by using decrypted secret-key for encryption and transfers encrypted electronic commerce data to said mediator; said mediator decrypts said encrypted electronic commerce data by using said secret-key for encryption, re-encrypts decrypted electronic commerce data by using secret-key for re-encryption, and transfers it together with said secret-key for re-encryption, which is encrypted by using public-key of said user, to said user; said user decrypts encrypted secret-key for re-encryption, decrypts encrypted electronic commerce data by using decrypted secret-key for re-encryption, makes order sheet by entering order content into decrypted electronic commerce data, encrypts said order sheet by using secret-key for re-encryption, and transfers encrypted order sheet to said mediator; said mediator decrypts said encrypted order sheet by using said secret-key for re-encryption, encrypts decrypted said order form by using public-key of said maker, and transfers encrypted order sheet to said maker; said maker decrypts encrypted order sheet by using private-key of said maker, and makes order acceptance.
58 . An electronic commerce system according to claim 57 , wherein said electronic commerce data has general file structure and data body thereof only is encrypted.
59 . An electronic commerce system according to claim 58 , wherein a part of said data body is encrypted.
60 . An electronic commerce system according to claim 59 , wherein the part of said data body with encrypted is repeatedly arranged in said data body.
61 . An electronic commerce system according to claim 59 , wherein a plurality of parts of said data body with encrypted is intermittently arranged in said data body.
62 . An electronic commerce system according to claim 57 , wherein said electronic commerce data has general file structure, and data header and data body thereof are encrypted.
63 . An electronic commerce system according to claim 62 , wherein a part of said data header and entire part of said data body are encrypted.
64 . An electronic commerce system according to claim 62 , wherein a part of said data header and a part of said data body are encrypted respectively.
65 . An electronic commerce system according to claim 57 , wherein said electronic commerce data has general file structure and data header thereof only is encrypted.
66 . An electronic commerce system according to claim 65 , wherein entire part of said data header is encrypted.
67 . An electronic commerce system according to claim 65 , wherein a part of said data header only is encrypted.
68 . An electronic commerce system according to claim 57 , wherein said electronic commerce data has general file structure and label only is encrypted.
69 . An electronic commerce system according to claim 68 , wherein a part of said label only is encrypted.
70 . An electronic commerce system according to claim 57 , wherein said electronic commerce data has object-formed file structure and method is encrypted.Join the waitlist — get patent alerts
Track US2002025044A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.