US2006185022A1PendingUtilityA1

Authoring system, authoring key generator, authoring device, authoring method, and data supply device, information terminal and information distribution method

Assignee: SONY CORPPriority: Aug 22, 2001Filed: Apr 18, 2006Published: Aug 17, 2006
Est. expiryAug 22, 2021(expired)· nominal 20-yr term from priority
H04L 9/40H04L 63/08H04L 63/0428H04L 2463/101H04L 63/104H04L 63/06
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An authoring system which authors content data to be distributed through an information terminal by encryption for copyright protection includes an authoring device and an authoring key generator. The authoring key generator generates a content identifier (CID) uniquely allocated to each of the content data (Content), an authoring key enabling key (CEK) uniquely allocated to the authoring device, and an authoring key (CED) obtained by encrypting a content key (Kc) for encrypting the content data and a second content key (EKc) using the CID and the CEK. The second content key (Ekc) is formed by encrypting the content key (Kc) using a root key (Kroot). The authoring device has a unit which decrypts the content key (Kc) and the second content key (Ekc) using the CID and the CEK, and a unit which encrypts the content data using the decrypted content key (Kc) to generate authored encrypted content data (E (Kc, Content)). For proper external authentication, a device which supplies the content data from an information terminal to a storage medium includes a unit which holds a first external authentication key securely; a unit which generates random numbers; a unit which encrypts the random numbers using the first external authentication key to generate first encrypted data; a unit which sends the random numbers to the information terminal; a unit which receives, from the information terminal, second encrypted data obtained by encrypting the random numbers using a second external authentication key equal to the first one; and a unit which compares the first and second encrypted data.

Claims

exact text as granted — not AI-modified
1 . A data supply device for supplying content data stored in an information terminal to a given storage medium, the device comprising: 
 key holding means for holding a first external authentication key securely;    random number generating means for generating random numbers;    encrypting means for encrypting the random numbers using the first external authentication key to generate first encrypted data;    sending means for sending the random numbers to the information terminal;    receiving means for receiving second encrypted data, the second encrypted data being obtained by encrypting the random numbers using a second external authentication key equal to the first external authentication key; and    comparing means for comparing the first encrypted data with the second encrypted data.    
   
   
       2 . The data supply device as claimed in  claim 1 , wherein the comparing means enables the content data to be supplied to the given storage medium when the first encrypted data coincides with the second encrypted data.  
   
   
       3 . The data supply device as claimed in  claim 1 , wherein the second external authentication key is previously stored in the information terminal and the second encrypted data is formed in the information terminal.  
   
   
       4 . The data supply device as claimed in  claim 1 , wherein the information terminal acquires the second external authentication key from a key control unit and the second encrypted data is formed in the information terminal.  
   
   
       5 . The data supply device as claimed in  claim 1 , wherein the random numbers are sent through the information terminal to a key control unit, and the second encrypted data is obtained by encrypting the random numbers within the key control unit using the second external authentication key.  
   
   
       6 . An information terminal for storing content data to be distributed, comprising: 
 first encrypting means for controlling encryption of random numbers generated within a data supply device using a first external authentication key securely held within the data supply device to generate first encrypted data;    second encrypting means for receiving the random numbers from the data supply device and for acquiring second encrypted data by encrypting the random numbers using a second external authentication key equal to the first external authentication key; and    licensing means for permitting the data supply device to supply the content data to a given storage medium only when the first encrypted data coincides with the second encrypted data.    
   
   
       7 . The information terminal as claimed in  claim 6 , wherein the second encrypting means stores the second external authentication key in advance and generates the second encrypted data within the information terminal.  
   
   
       8 . The information terminal as claimed in  claim 6 , wherein the second encrypting means obtains the second external authentication key from a key control unit and generates the second encrypted data within the information terminal.  
   
   
       9 . The information terminal as claimed in  claim 6 , wherein the second encrypting means sends the random numbers to a key control unit and acquires the second encrypted data from the key control unit.  
   
   
       10 . A data supply device, comprising: 
 recording means for recording content data recorded in an information terminal to a given storage medium;    data record control means for controlling operation of the recording means;    first authentication means for determining whether the content data has been generated by a legal authoring system; and    second authentication means for performing a mutual check between the recording means and the data record control means,    wherein the data record control means controls the recording means to record the content data to the given storage medium only when the content data has been generated by a legal authoring system and the mutual check is successful.    
   
   
       11 . The data supply device as claimed in  claim 10 , wherein the first authentication means determines whether the content data has been generating by a legal authoring system by referring to a MAC written in the content data by the legal authoring system.  
   
   
       12 . The data supply device as claimed in  claim 10 , wherein the second authentication means transfers a content enabling key (EKB), obtained by encrypting a root key (Kroot) using a device key (Kdevice) of the legal authoring system, to the data record control means and the recording means; the data record control means decrypts the root key (Kroot) using a device key (Kdevice) of the data record control means to obtain a first decrypted root key; and the recording means decrypts the root key (Kroot) using a device key (Kdevice) of the recording means to obtain a second decrypted root key; wherein the mutual check is successful when the first decrypted root key coincides with the second decrypted root key.  
   
   
       13 . The data supply device as claimed in  claim 10 , further comprising reproduction control means for controlling reproduction of the content data in the given storage medium.  
   
   
       14 . The data supply device as claimed in  claim 13 , wherein the recording means records plural content data to the given storage medium, and the reproduction control means permits reproduction of the plural content data only after the plural content data has been recorded to the given storage medium.  
   
   
       15 . A method for supplying content data stored in an information terminal to a given storage medium, the method comprising: 
 generating random numbers;    encrypting the random numbers using a securely held first external authentication key to generate first encrypted data;    sending the random numbers to the information terminal;    encrypting the random numbers using a second external authentication key equal to the first external authentication key;    receiving the second encrypted data from the information terminal; and    comparing the first encrypted data with the second encrypted data.    
   
   
       16 . The content data supply method as claimed in  claim 15 , further comprising: 
 supplying the content data to the storage medium when the first encrypted data coincides with the second encrypted data.    
   
   
       17 . The content data supply method as claimed in  claim 15 , further comprising: 
 storing the second external authentication key in the information terminal prior to the step of encrypting the random numbers within the information terminal.    
   
   
       18 . The content data supply method as claimed in  claim 15 , further comprising: 
 supplying the second external authentication key from a key control unit to the information terminal prior to the step of encrypting the random numbers within the information terminal.    
   
   
       19 . The content data supply method as claimed in  claim 15 , further comprising: 
 sending the random numbers through the information terminal to a key control unit; and    encrypting the random numbers within the key control unit using the second external authentication key.    
   
   
       20 . An information supply method used in a data supply device having recording means for recording content data from an information terminal to a given storage medium and data record control means for controlling operation of the recording means, the method comprising: 
 determining whether the content data has been generated by a legal authoring system;    performing a mutual check between the recording means and the data record control means; and    recording the content data to the given storage medium only when the content data has been generated by a legal authoring system and the mutual check is successful.    
   
   
       21 . The information supply method as claimed in  claim 20 , wherein the step of determining whether the content data has been generated by a legal authoring system includes referring to a MAC written in the content data by the legal authoring system.  
   
   
       22 . The information supply method as claimed in  claim 20 , wherein the second authentication step includes transferring a content enabling key (EKB), obtained by encrypting a root key (Kroot) using a device key (Kdevice) of the legal authoring system, to the data record control means and the recording means; decrypting the root key (Kroot) using a device key (Kdevice) of the data record control means to obtain a first decrypted root key; and decrypting the root key (Kroot) using a device key (Kdevice) of the recording means to obtain a second decrypted root key; and wherein the mutual check is successful when the first decrypted root key coincides with the second decrypted root key.  
   
   
       23 . The information supply method as claimed in  claim 20 , further comprising: 
 reproducing the content data in the given storage medium.    
   
   
       24 . The information supply method as claimed in  claim 23 , wherein the recording step includes recording plural content data to the given storage medium, and the reproducting step reproduces the plural content data only after the plural content data has been recorded to the given storage medium.

Join the waitlist — get patent alerts

Track US2006185022A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.