US2007185813A1PendingUtilityA1

Cryptographic methods, apparatus and systems for storage media electronic rights management in closed and connected appliances

Assignee: INTERTRUST TECH CORPPriority: Feb 13, 1995Filed: May 9, 2006Published: Aug 9, 2007
Est. expiryFeb 13, 2015(expired)· nominal 20-yr term from priority
G06Q 40/12H04L 2463/101G06F 2211/007G06Q 20/1235G06Q 30/06H04L 63/10G06F 21/6209G06Q 30/0609H04N 21/83555H04N 21/435H04L 2463/103H04L 9/0838H04N 21/4627G06Q 20/102H04N 7/162G06Q 50/188H04L 63/083H04L 9/3247H04N 21/2543G06Q 40/02H04N 2005/91364H04L 2209/56G06Q 30/0601H04L 9/3218H04L 63/123H04L 9/006H04L 9/0861H04N 21/8355H04N 21/6581H04L 63/168H04N 21/235H04N 21/2362G06F 21/71H04L 63/20G06T 1/0021G06F 21/33H04L 63/08G06Q 20/04G06Q 20/12H04L 9/0819G06F 2221/2151G06Q 20/123H04L 63/04H04N 7/17309G06Q 20/24H04L 63/02H04N 21/23476H04L 63/0435H04N 21/2547H04N 21/2347G06Q 20/10H04N 21/835G06Q 20/085H04N 21/4345H04N 21/4143H04L 63/0823H04L 9/3263G06Q 40/04H04N 21/4405H04N 21/8358G06Q 30/0283H04N 21/4325H04N 21/4753G06F 21/86G06Q 30/0273H04N 21/8166G07F 9/026H04N 21/42646H04L 63/0442H04N 21/44204G06F 2221/2137H04L 2463/102H04L 63/16H04N 5/913G06Q 20/02G06F 2221/2135H04N 21/25875G06Q 20/023G06Q 20/14H04N 7/163H04L 63/0428G06F 21/31G06F 2221/2101H04N 21/2541H04L 2209/60G06Q 10/087H04N 21/443G06Q 2220/16G06Q 50/184G06Q 20/308H04L 63/12G06Q 20/306G06F 21/109G06F 21/16
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A rights management arrangement for storage media such as optical digital video disks (DVDs, also called digital versatile disks) provides adequate copy protection in a limited, inexpensive mass-produceable, low-capability platform such as a dedicated home consumer disk player and also provides enhanced, more flexible security techniques and methods when the same media are used with platforms having higher security capabilities. A control object (or set) defines plural rights management rules for instance, price for performance or rules governing redistribution. Low capability platforms may enable only a subset of the control rules such as controls on copying or marking of played material. Higher capability platforms may enable all (or different subsets) of the rules. Cryptographically strong security is provided by encrypting at least some of the information carried by the media and enabling decryption based on the control set and/or other limitations. A secure “software container” can be used to protectively encapsulate (e.g., by cryptographic techniques) various digital property content (e.g., audio, video, game, etc.) and control object (i.e., set of rules) information. A standardized container format is provided for general use on/with various mediums and platforms. In addition, a special purpose container may be provided for DVD medium and appliances (e.g., recorders, players, etc.) that contains DVD program content (digital property) and DVD medium specific rules. The techniques, systems and methods disclosed herein are capable of achieving compatibility with other protection standards, such as for example, CGMA and Matsushita data protection standards adopted for DVDs. Cooperative rights management may also be provided, where plural networked rights management arrangements collectively control a rights management event on one or more of such arrangements.

Claims

exact text as granted — not AI-modified
1 . An electronic appliance for accessing or otherwise using protected information stored on a storage medium, the electronic appliance comprising: 
 a disk drive configured to read the protected information from the storage medium; and    a protected processing environment communicatively coupled to the disk drive, the protected processing environment being configured to (a) access a control set associated with the protected information, the control set including two or more controls specifying one or more permitted uses of the protected information, the control set including at least (i) a first control requiring for its application one or more capabilities of the electronic appliance, and (ii) a second control that does not require, for its application, said one or more capabilities, (b) determine that the electronic appliance has the one or more capabilities, and (c) selectively permit the electronic appliance to access or otherwise use the protected information in accordance with at least the first control.    
     
     
         2 . The electronic appliance of  claim 1 , in which the protected processing environment is configured to obtain identification information of the protected information stored on the storage medium, and in which the protected processing environment is coupled to a network, and is configured to obtain the control set from a remote site over the network based at least in part on the identification information.  
     
     
         3 . The electronic appliance of  claim 2 , in which the remote site comprises a rights clearinghouse.  
     
     
         4 . The electronic appliance of  claim 1 , in which the one or more capabilities includes a capability to enforce a condition associated with a permitted use specified by the first control.  
     
     
         5 . The electronic appliance of  claim 4 , in which the permitted use specified by the first control comprises copying the protected information, and in which the condition specifies a predefined number of copies that may be made.  
     
     
         6 . The electronic appliance of  claim 5 , in which the predefined number is greater than one, and in which the second control specifies that copying the protected information is permitted only one time.  
     
     
         7 . The electronic appliance of  claim 4 , in which the condition comprises a requirement that auditing information be collected regarding the permitted use specified by the first control.  
     
     
         8 . The electronic appliance of  claim 4 , in which the condition comprises a requirement that a user of the electronic appliance possess certain identity information.  
     
     
         9 . The electronic appliance of  claim 8 , in which the identity information comprises a digital certificate attesting to the user's identity or membership in a class.  
     
     
         10 . The electronic appliance of  claim 4 , in which the condition comprises a requirement that a user of the electronic appliance make a payment.  
     
     
         11 . The electronic appliance of  claim 1 , in which the one or more capabilities includes having a network connection.  
     
     
         12 . The electronic appliance of  claim 1 , in which the protected processing environment comprises one or more decryption keys, and in which the protected processing environment is further configured to use the one or more decryption keys to decrypt the protected information.  
     
     
         13 . The electronic appliance of  claim 12 , in which said use of the one or more decryption keys to decrypt the protected information comprises using the one or more decryption keys to decrypt one or more encrypted content decryption keys and using the one or more content decryption keys to decrypt the protected information.  
     
     
         14 . The electronic appliance of  claim 1 , in which the protected processing environment comprises a secure processing unit, the secure processing unit comprising a microprocessor and memory storing one or more cryptographic keys for use in decrypting one or more encrypted content decryption keys stored on the storage medium.  
     
     
         15 . The electronic appliance of  claim 1 , in which the control set includes one or more controls selected from a group consisting of: a control that prohibits copying of the protected information, a control that allows the protected information to be copied only once, a control that allows the protected information to be copied multiple times, a control that allows a user or a class of users to play the protected information, and a control that allows a user or a class of users to extract or excerpt at least a part of the protected information.  
     
     
         16 . The electronic appliance of  claim 1 , in which the first control specifies that the protected information can only be released to one or more types of devices.  
     
     
         17 . The electronic appliance of  claim 16 , in which the one or more types of devices includes devices that are not configured to copy the protected information.  
     
     
         18 . The electronic appliance of  claim 16 , in which the one or more types of devices includes devices that are configured to enforce at least part of the control set.  
     
     
         19 . The electronic appliance of  claim 1 , in which the electronic appliance comprises a DVD player.  
     
     
         20 . The electronic appliance of  claim 1 , in which the electronic appliance comprises a computer.  
     
     
         21 . A method of accessing or otherwise using protected information, the method comprising: 
 receiving a request from a user of an electronic appliance to access or otherwise use protected information;    using a protected processing environment of the electronic appliance to access a control set associated with the protected information, the control set including two or more controls specifying one or more permitted uses of the protected information, the control set including at least (i) a first control requiring, for its application, one or more capabilities of the electronic appliance, and (ii) a second control that does not require, for its application, said one or more capabilities;    determining that the electronic appliance is capable of applying the first control; and    using the protected processing environment to selectively grant or deny the request in accordance with at least the first control.    
     
     
         22 . The method of  claim 21 , in which the one or more capabilities include a capability to enforce a condition associated with a permitted use specified by the first control.  
     
     
         23 . The method of  claim 22 , in which the permitted use specified by the first control comprises copying the protected information, and in which the condition specifies a predefined number of copies that may be made.  
     
     
         24 . The method of  claim 23 , in which the request comprises a request to copy the protected information, the method further comprising: 
 determining that the protected information has not been copied said predefined number of times;    making a copy of the protected information; and    storing an indication that the protected information has been copied.    
     
     
         25 . The method of  claim 23 , in which the predefined number is greater than one, and in which the request comprises a request to copy the protected information, the method further comprising: 
 determining that the protected information has not been copied said predefined number of times; and    making a copy of the protected information.    
     
     
         26 . The method of  claim 22 , in which the condition comprises collecting auditing information regarding the permitted use specified by the first control.  
     
     
         27 . The method of  claim 22 , in which the condition comprises verifying that the user possesses certain identity information, the method further comprising: 
 obtaining the identity information;    wherein the step of using the protected processing environment to selectively grant or deny the request is further based at least in part on the identity information.    
     
     
         28 . The method of  claim 27 , in which the identity information comprises a digital certificate attesting to the user's identity or a class to which the user belongs.  
     
     
         29 . The method of  claim 22 , in which the condition comprises determining that the user has made a payment.  
     
     
         30 . The method of  claim 21 , in which the step of using the protected processing environment of the electronic appliance to access a control set includes obtaining the control set from a remote site over a telecommunications network.  
     
     
         31 . The method of  claim 21 , in which the protected processing environment comprises one or more decryption keys, the method further comprising: 
 using the one or more decryption keys to decrypt the protected information.    
     
     
         32 . The method of  claim 31 , in which the protected processing environment includes a secure processing unit having internal memory, in which the step of using the one or more decryption keys to decrypt the protected information includes retrieving the one or more decryption keys from the internal memory of the secure processing unit.  
     
     
         33 . The method of  claim 31 , in which the step of using the one or more decryption keys to decrypt the protected information includes using the one or more decryption keys to decrypt one or more content keys stored on a storage medium containing the protected information, and using the one or more content keys to decrypt the protected information.  
     
     
         34 . The method of  claim 21 , in which the control set includes one or more controls selected from a group consisting of: a control that prohibits copying of the protected information, a control that allows the protected information to be copied only once, and a control that allows the protected information to be copied multiple times.  
     
     
         35 . The method of  claim 21 , in which the control set includes one or more controls selected from a group consisting of: a control that allows a user or a class of users to play the protected information, and a control that allows a user or a class of users to extract or excerpt at least a part of the protected information.  
     
     
         36 . The method of  claim 21 , in which the control set includes two or more controls selected from a group consisting of: a control that prohibits copying of the protected information, a control that allows the protected information to be copied only once, a control that allows the protected information to be copied multiple times, a control that allows a user or a class of users to play the protected information, and a control that allows a user or a class of users to extract or excerpt at least a part of the protected information.  
     
     
         37 . The method of  claim 21 , in which the first control specifies that the protected information can only be released to devices that are not configured to copy the protected information.  
     
     
         38 . The method of  claim 21 , in which the first control specifies that copies of the protected information be degraded in quality.  
     
     
         39 . A method performed by an electronic appliance, the method comprising: 
 receiving a removable storage medium in a drive of the electronic appliance, the removable storage medium containing a protected content item and a control set comprising at least two controls, each of said at least two controls specifying one or more permitted or prohibited uses of the protected content item;    parsing the control set;    disregarding at least one control that the electronic appliance is unable to enforce; and    in response to a request to access the protected content item, responding to the request in accordance with at least one control that the electronic appliance is able to enforce.    
     
     
         40 . The method of  claim 39 , in which the request comprises a request to copy the protected content item, and in which the at least one control that the electronic appliance is able to enforce comprises a control specifying that copying is prohibited, and in which the step of responding to the request comprises denying the request.  
     
     
         41 . The method of  claim 39 , in which the request comprises a request to copy the protected content item, and in which the at least one control that the electronic appliance is able to enforce comprises a control specifying that the protected content item can be copied only a predefined number of times, the method further comprising: 
 determining that the protected content item has not been copied said predefined number of times; and    making a copy of the protected content item.    
     
     
         42 . The method of  claim 41 , in which the predefined number is greater than one.  
     
     
         43 . The method of  claim 39 , in which the at least one control that the electronic appliance is unable to enforce comprises a control that requires auditing.  
     
     
         44 . The method of  claim 39 , in which the at least one control that the electronic appliance is unable to enforce includes a condition that the electronic appliance is unable to enforce.  
     
     
         45 . The method of  claim 39 , in which the at least one control that the electronic appliance is unable to enforce comprises a control that the electronic appliance is unable to interpret.  
     
     
         46 . A method performed by an electronic appliance, the method comprising: 
 receiving a protected content item and a control set comprising at least two controls, each of the at least two controls specifying one or more permitted or prohibited uses of the protected content item, the control set including a first control that the electronic appliance is unable to enforce and a second control that the electronic appliance is able to enforce;    receiving a request from a user of the electronic appliance to use the protected content item; and    responding to the request in accordance with at least the second control.    
     
     
         47 . The method of  claim 46 , in which the request comprises a request to copy the protected content item, and in which the second control comprises a control specifying that copying is prohibited, and in which the step of responding to the request comprises denying the request.  
     
     
         48 . The method of  claim 46 , in which the request comprises a request to copy the protected content item, and in which the second control comprises a control specifying that the protected content item can be copied only a predefined number of times, the method further comprising: 
 determining that the protected content item has not been copied said predefined number of times;    making a copy of the protected content item; and    storing an indication that the protected content item has been copied.    
     
     
         49 . The method of  claim 48 , in which the predefined number is greater than one.  
     
     
         50 . The method of  claim 46 , in which the first control comprises a control that requires auditing.  
     
     
         51 . The method of  claim 46 , in which the first control specifies a condition associated with a permitted use of the protected content item, and in which the electronic appliance is unable to enforce the condition.  
     
     
         52 . The method of  claim 46 , in which the first control comprises a control that the electronic appliance is unable to interpret.  
     
     
         53 . The method of  claim 51 , further comprising: 
 receiving an additional request from the user of the electronic appliance to make the permitted use of the protected content with which the condition is associated;    determining that the electronic appliance is unable to enforce the condition; and    denying the request.    
     
     
         54 . A method performed by an electronic appliance, the method comprising: 
 receiving a protected content item and a control set comprising at least two controls, each of the at least two controls specifying one or more permitted or prohibited uses of the protected content item;    receiving a first request from a user of the electronic appliance to make a use of the protected content item that is specified in a control that the electronic appliance is unable to enforce; and    denying the first request.    
     
     
         55 . The method of  claim 54 , further comprising: 
 receiving a second request from a user of the electronic appliance to make a use of the protected content item that is specified in a control that the electronic appliance is able to enforce; and    granting the request.    
     
     
         56 . A method performed by an electronic appliance, the method comprising: 
 receiving a protected content item and a control set specifying one or more permitted uses of the protected content item;    receiving a request to make a requested use of the protected content item;    parsing the control set;    determining that the control set includes a control permitting the requested use, but that the control set further includes a condition associated with the requested use;    determining that the electronic appliance is unable to enforce the condition; and    denying the request.    
     
     
         57 . The method of  claim 56 , in which the request comprises a request to make at least a second copy of the protected content item, and in which the electronic appliance is not configured to maintain a count of copies.  
     
     
         58 . The method of  claim 56 , in which the request comprises a request to play the protected content item, and in which the condition comprises collecting auditing information associated with playing the protected content item.  
     
     
         59 . The method of  claim 56 , in which the condition comprises collecting auditing information.  
     
     
         60 . The method of  claim 56 , in which the condition comprises collecting a payment.  
     
     
         61 . The method of  claim 56 , in which the condition comprises verifying identity information of a user of the electronic appliance.  
     
     
         62 . An electronic appliance comprising: 
 an input for receiving protected digital information;    a user interface for receiving a request from a user of the electronic appliance to make a requested use of the protected digital information;    hardware and/or software configured to: (a) access a control set associated with the protected digital information, the control set including at least (i) a first control specifying a first permitted use of the protected digital information, and (ii) a second control specifying a second permitted use of the protected digital information and a condition associated with the second permitted use, wherein the electronic appliance is not configured to enforce the condition; (b) determine whether the requested use corresponds to the first permitted use or the second permitted use; (c) grant the request in accordance with at least the first control if the requested use corresponds to the first permitted use; and (d) deny the request if the requested use corresponds to the second permitted use; and    an output for presenting the protected digital information to the user.    
     
     
         63 . The electronic appliance of  claim 62 , in which the condition comprises collecting auditing information.  
     
     
         64 . The electronic appliance of  claim 62 , in which the condition comprises collecting a payment from the user.  
     
     
         65 . The electronic appliance of  claim 62 , in which the condition comprises verifying identity information of the user.  
     
     
         66 . The electronic appliance of  claim 62 , in which the condition comprises a limit on a number of times the second permitted use can be made.  
     
     
         67 . The electronic appliance of  claim 66 , in which the second permitted use comprises copying the protected digital information.  
     
     
         68 . An electronic appliance comprising: 
 an input for receiving protected digital information;    a user interface for receiving a request from a user of the electronic appliance to use the protected digital information;    a rights management component configured to (a) access a control set associated with the protected digital information, the control set including two or more controls specifying one or more permitted uses of the protected digital information, the control set including at least (i) a first control requiring, for its application, one or more capabilities of the electronic appliance, and (ii) a second control that does not require, for its application, said one or more capabilities, (b) determine that the electronic appliance has the one or more capabilities, and (c) selectively permit the user to use the protected digital information in accordance with at least the first control; and    an output for presenting the protected digital information to the user.    
     
     
         69 . The electronic appliance of  claim 68 , in which the one or more capabilities include a capability to enforce a condition associated with a permitted use specified by the first control.  
     
     
         70 . The electronic appliance of  claim 69 , in which the permitted use specified by the first control comprises copying the protected digital information, and the condition comprises a limit on a number of copies that may be made.  
     
     
         71 . The electronic appliance of  claim 70 , in which the limit is greater than one.  
     
     
         72 . The electronic appliance of  claim 71 , in which the rights management component is further configured to: determine that the protected digital information has not been copied said predefined number of times; permit the user to make a copy of the protected digital information; 
 and store an indication that the protected digital information has been copied.    
     
     
         73 . The electronic appliance of  claim 71 , in which the second control specifies that copying the protected digital information is permitted, and further specifies a condition that the protected digital information may only be copied once, wherein the one or more capabilities include a capability to maintain a count of copies.  
     
     
         74 . The electronic appliance of  claim 69 , in which the condition comprises collecting auditing information regarding the permitted use specified by the first control.  
     
     
         75 . The electronic appliance of  claim 69 , in which the condition comprises collecting a payment from the user.  
     
     
         76 . The electronic appliance of  claim 69 , in which the condition comprises verifying identity information of the user.  
     
     
         77 . The electronic appliance of  claim 69 , in which the condition comprises a limit on a number of times the permitted use specified by the first control can be made.  
     
     
         78 . The electronic appliance of  claim 76 , in which the identity information comprises a digital certificate attesting to the user's identity or membership in a class.  
     
     
         79 . The electronic appliance of  claim 68 , in which the control set includes one or more controls selected from a group consisting of: a control that allows a user or a class of users to play the protected digital information, and a control that allows a user or a class of users to extract or excerpt at least a part of the protected digital information.  
     
     
         80 . The electronic appliance of  claim 68 , in which the control set includes two or more controls selected from a group consisting of: a control that prohibits copying of the protected digital information, a control that allows the protected digital information to be copied only once, a control that allows the protected digital information to be copied multiple times, a control that allows a user or a class of users to play the protected digital information, and a control that allows a user or a class of users to extract or excerpt at least a part of the protected digital information.  
     
     
         81 . The electronic appliance of  claim 68 , in which the electronic appliance is coupled to a network, and is configured to obtain the control set from a remote site over the network.  
     
     
         82 . The electronic appliance of  claim 68 , in which the electronic appliance comprises one or more decryption keys, and in which the electronic appliance is further configured to use the one or more decryption keys to decrypt the protected digital information.  
     
     
         83 . The electronic appliance of  claim 68 , in which the control set includes a control specifying that the protected digital information can only be released to one or more types of devices.  
     
     
         84 . The electronic appliance of  claim 83 , in which the one or more types of devices includes devices that are not configured to copy the protected digital information.  
     
     
         85 . The electronic appliance of  claim 83 , in which the one or more types of devices includes devices that are configured to enforce at least part of the control set.  
     
     
         86 . The electronic appliance of  claim 68 , in which the control set includes a control specifying that the protected digital information be fingerprinted prior to release by the electronic appliance.  
     
     
         87 . The electronic appliance of  claim 68 , in which the control set includes a control specifying that copies of the protected digital information be degraded in quality.  
     
     
         88 . The electronic appliance of  claim 68 , in which the rights management component comprises a secure processing unit comprising a microprocessor and memory storing one or more cryptographic keys for use in decrypting the protected digital information.  
     
     
         89 . A system comprising: 
 a control set for governing use of protected digital information, the control set including two or more subsets of rights management rules, the two or more subsets being based, at least in part, on one or more electronic appliance capabilities related to complying with rights management rules; and    an electronic appliance adapted to apply the control set to govern use of the protected digital information, the electronic appliance including a processor adapted to (a) make a selection of at least one of the two or more subsets of rights management rules, the selection being based at least in part on one or more capabilities of the electronic appliance, and (b) use at least a part of the protected digital information in accordance with the selection of rights management rules.    
     
     
         90 . The system of  claim 89 , in which the control set includes a first subset of rights management rules corresponding to capabilities of a disk player.  
     
     
         91 . The system of  claim 90 , in which the first subset of rights management rules includes one or more rules relating to copying the protected digital information.  
     
     
         92 . The system of  claim 90 , in which the control set includes a second subset of rights management rules corresponding to capabilities of a networked computer.  
     
     
         93 . The system of  claim 92 , in which the second subset of rights management rules includes one or more rules relating to auditing use of the protected digital information.  
     
     
         94 . The system of  claim 89 , in which the control set and the protected digital information are stored on a portable storage medium, and in which the electronic appliance is configured to read the protected digital information and the control set from the portable storage medium.  
     
     
         95 . The system of  claim 89 , in which the electronic appliance is coupled to a network and is adapted to access the control set through the network.  
     
     
         96 . The system of  claim 89 , in which the two or more subsets of rights management rules include a first subset for electronic appliances that are not connected to a network, and a second subset for electronic appliances that are connected to a network.  
     
     
         97 . The system of  claim 96 , in which the second subset enables more extensive use of the protected digital information than the first subset.  
     
     
         98 . The system of  claim 89 , in which the processor is configured to obtain identification information of a user of the electronic appliance, and in which the selection of at least one of the two or more subsets of rights management rules is further based at least in part on the identification information.  
     
     
         99 . A method of governing use of protected digital information by an electronic appliance, the method comprising: 
 determining one or more capabilities of the electronic appliance in complying with rights management rules included in a control set; and    using a subset of the rights management rules included in the control set to govern use of the protected digital information by the electronic appliance, the subset of rights management rules corresponding to capabilities of the electronic appliance in complying therewith.    
     
     
         100 . The method of  claim 99 , in which the electronic appliance comprises a disk player and in which the subset of the rights management rules includes one or more rights management rules that the disk player is able to enforce.  
     
     
         101 . The method of  claim 100 , in which the one or more rights management rules that the disk player is able to enforce include one or more rules relating to copying the protected digital information.  
     
     
         102 . The method of  claim 100 , in which the control set further includes a second subset of rights management rules that the disk player is unable to enforce.  
     
     
         103 . The method of  claim 102 , in which the second subset of rights management rules includes one or more rules requiring use of the protected digital information to be audited.  
     
     
         104 . The method of  claim 99 , which the electronic appliance comprises a networked computer.  
     
     
         105 . The method of  claim 99 , further comprising: 
 receiving the protected digital information; and    separately receiving the control set over a telecommunications network to which the electronic appliance is communicatively coupled.    
     
     
         106 . The method of  claim 99 , in which determining one or more capabilities of the electronic appliance includes determining whether the electronic appliance is connected to a network.  
     
     
         107 . The method of  claim 99 , in which the control set includes at least two subsets of rights management rules, the at least two subsets including a first subset for appliances that are capable of being connected to a network, and a second subset for appliances that are not capable of being connected to a network.  
     
     
         108 . The method of  claim 107 , in which the second subset enables more extensive use of the protected digital information than the first subset.

Join the waitlist — get patent alerts

Track US2007185813A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.