Cryptographic methods, apparatus and systems for storage media electronic rights management in closed and connected appliances
Abstract
A rights management arrangement for storage media such as optical digital video disks (DVDs, also called digital versatile disks) provides adequate copy protection in a limited, inexpensive mass-produceable, low-capability platform such as a dedicated home consumer disk player and also provides enhanced, more flexible security techniques and methods when the same media are used with platforms having higher security capabilities. A control object (or set) defines plural rights management rules for instance, price for performance or rules governing redistribution. Low capability platforms may enable only a subset of the control rules such as controls on copying or marking of played material. Higher capability platforms may enable all (or different subsets) of the rules. Cryptographically strong security is provided by encrypting at least some of the information carried by the media and enabling decryption based on the control set and/or other limitations. A secure “software container” can be used to protectively encapsulate (e.g., by cryptographic techniques) various digital property content (e.g., audio, video, game, etc.) and control object (i.e., set of rules) information. A standardized container format is provided for general use on/with various mediums and platforms. In addition, a special purpose container may be provided for DVD medium and appliances (e.g., recorders, players, etc.) that contains DVD program content (digital property) and DVD medium specific rules. The techniques, systems and methods disclosed herein are capable of achieving compatibility with other protection standards, such as for example, CGMA and Matsushita data protection standards adopted for DVDs. Cooperative rights management may also be provided, where plural networked rights management arrangements collectively control a rights management event on one or more of such arrangements.
Claims
exact text as granted — not AI-modified1 . A system comprising:
a first electronic appliance configured to receive a request from a user to use protected information, the first electronic appliance including a rights management component configured to determine whether the first electronic appliance has sufficient rights to grant the request; and one or more other appliances, each of the one or more other appliances including a rights management component; wherein the rights management component of the first electronic appliance is configured to obtain, from at least one of the one or more other appliances, rights that the first electronic appliance needs to grant the request.
2 . The system of claim 1 , in which the rights management component of the first electronic appliance is configured to determine whether the first electronic appliance has sufficient rights to grant the request based at least in part on property information of the first electronic appliance.
3 . The system of claim 2 , in which the property information of the first electronic appliance includes a security level of the first electronic appliance.
4 . The system of claim 1 , in which the rights management component of the first electronic appliance is configured to determine whether the first electronic appliance has sufficient rights to grant the request based at least in part on identification information of the user of the first electronic appliance.
5 . The system of claim 1 , in which the rights management component of the first electronic appliance is configured to determine whether the first electronic appliance has sufficient rights to grant the request based at least in part on a context within which the first electronic appliance is operating.
6 . The system of claim 5 , in which the context includes characteristics of a network to which the first electronic appliance is connected.
7 . The system of claim 1 , in which the first electronic appliance is coupled to at least one of the one or more other appliances through a server.
8 . The system of claim 7 , in which the server includes information regarding identities of one or more other appliances having rights that the first electronic appliance needs for making certain uses of the protected information.
9 . The system of claim 1 , in which the one or more other appliances include at least one appliance that possesses greater rights management capabilities than the first electronic appliance.
10 . The system of claim 1 , in which the first electronic appliance is a portable device, and in which the at least one of the one or more other appliances is a computer comprising rights management software and/or hardware.
11 . The system of claim 10 , in which the first electronic appliance is coupled to the at least one of the one or more other appliances through a serial bus.
12 . The system of claim 11 , in which the serial bus is compliant at least in part with the IEEE 1394-1995 high speed serial bus standard
13 . The system of claim 1 , in which the first electronic appliance and/or the at least one of the one or more other appliances includes a control specifying one or more rights in the protected information, the one or more rights selected from a group consisting of: allowing the protected information to be copied only once, allowing the protected information to be copied multiple times, allowing a user or a class of users to play the protected information, and allowing a user or a class of users to extract or excerpt at least a part of the protected information.
14 . The system of claim 1 , in which the rights management component of the at least one of the one or more other appliances includes a secure processing unit.
15 . The system of claim 1 , in which the rights management component of the first electronic appliance comprises a protected processing environment, and in which the first electronic appliance is configured to (a) obtain, from the at least one of the one or more other appliances, a control set including the rights that the first appliance needs to grant the request, and (b) use the protected processing environment to securely grant the request in accordance with the control set.
16 . A method performed by tamper-resistant hardware and/or software running on a first electronic appliance, the method comprising:
receiving a request from a user of the first electronic appliance to make a requested use of protected information; determining whether the user has sufficient rights to make the requested use of the protected information; and upon determining that the user has insufficient rights to make the requested use of the protected information, obtaining one or more rights from at least one other appliance communicatively coupled to the first electronic appliance, the one or more rights being sufficient, either alone or in combination with other rights, to enable the user to make the requested use of the protected information.
17 . The method of claim 16 , in which the step of determining whether the first electronic appliance has sufficient rights to make the requested use of the protected information is based at least in part on property information of the first electronic appliance.
18 . The method of claim 17 , in which the property information includes a security level of the first electronic appliance.
19 . The method of claim 16 , in which determining whether the first electronic appliance has sufficient rights is based at least in part on identification information of the user.
20 . The method of claim 16 , in which determining whether the first electronic appliance has sufficient rights is based at least in part on a context within which the first electronic appliance is operating.
21 . The method of claim 20 , in which the context includes characteristics of a network to which the first electronic appliance is connected.
22 . The method of claim 16 , in which the first electronic appliance and the at least one other appliance are connected via a network.
23 . The method of claim 16 , in which the at least one other appliance is coupled to the first electronic appliance through a server connected to the first electronic appliance and the at least one other appliance.
24 . The method of claim 23 , in which the server includes information regarding identities of one or more appliances having rights that the first electronic appliance needs to make one or more uses of the protected information.
25 . The method of claim 16 , in which the at least one other appliance has greater rights management capabilities than the first electronic appliance.
26 . The method of claim 16 , in which the first electronic appliance is a portable device, and the at least one other appliance is a computer comprising rights management software and/or hardware.
27 . The method of claim 16 , in which the first electronic appliance is coupled to the at least one other appliance through a serial bus.
28 . The method of claim 16 , in which the first electronic appliance and/or the at least one other appliance includes a control specifying one or more rights in the protected information, the one or more rights selected from a group consisting of: allowing the protected information to be copied only once, allowing the protected information to be copied multiple times, allowing a user or a class of users to play the protected information, and allowing a user or a class of users to extract or excerpt at least a part of the protected information.
29 . The method of claim 16 , in which the first electronic appliance and the at least one other appliance each include a rights management component.
30 . The method of claim 29 , in which the rights management component of at least one of the first electronic appliance and the at least one other appliance includes a secure processing unit.
31 . The method of claim 29 , in which the rights management component of the first electronic appliance is configured to determine whether the first electronic appliance has sufficient rights to make the requested use of the protected information.Join the waitlist — get patent alerts
Track US2006200392A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.