Recording management system, control method, and program

The recording management system and terminal device encrypt and manage content on cloud servers, addressing unauthorized activities by controlling access and playback, enhancing security and access control.

JP2026104964APending Publication Date: 2026-06-25PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
Filing Date
2026-04-15
Publication Date
2026-06-25

AI Technical Summary

Technical Problem

Existing content transmission systems are inadequate in suppressing unauthorized activities related to content recorded on general-purpose cloud servers.

Method used

A recording management system and terminal device that encrypt content, manage validity determination information, and perform device authentication to control access and playback, ensuring appropriate suppression of unauthorized activities.

Benefits of technology

Effectively prevents unauthorized access and playback of content, maintaining security and appropriate access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026104964000001_ABST
    Figure 2026104964000001_ABST
Patent Text Reader

Abstract

We provide a recording management system that can effectively suppress unauthorized activities related to content. [Solution] The recording management system comprises a circuit and at least one memory, the at least one memory which holds validity determination information and a content key Kc associated with a general-purpose cloud service 20, the circuit reads the content key Kc from the at least one memory and uses it to encrypt the content, reads the validity determination information from the at least one memory and uses the validity determination information to determine the validity of the content recorded on the cloud server device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a technology used in a system for recording and playing back content such as a program to be distributed.

Background Art

[0002] Conventionally, a content transmission system including a content transmission device and a content reception device that safely transmit and receive content has been proposed (see, for example, Patent Document 1). In this content transmission system, the content transmission device performs mutual authentication and sharing key transfer with the content reception device, encrypts the content using an encryption key generated from the shared key, and transmits the content to the content reception device. At this time, the content transmission device switches the shared key to be transferred according to whether the content reception device has a predetermined security strength.

[0003] Also, within an appropriate range of use, a content transmission system for transmitting content stored in a home server to a terminal via an external network has been proposed (see, for example, Patent Document 2). In this content transmission system, the server permits transmission of content shorter than the playable time to a terminal that requests content by remote access, and reduces the playable time by the playback time of the content transmitted by remote access.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, when content is recorded on a general-purpose cloud server, the content transmission systems described in Patent Documents 1 and 2 have the problem of being unable to adequately suppress unauthorized activities related to that content.

[0006] Therefore, this disclosure provides terminal devices and the like that can appropriately suppress unauthorized activities related to content. [Means for solving the problem]

[0007] A recording management system according to one aspect of the present disclosure is a recording management system used in a recording playback system, the recording playback system includes a cloud server device, a recording management system that receives and encrypts distributed content and records the encrypted content on the cloud server device via the internet, and a terminal device that obtains an encrypted content key via the internet, decrypts the content key, and plays the content, the recording management system comprises a circuit and at least one memory, the at least one memory holds validity determination information and the content key associated with the cloud server device, the circuit reads the content key from the at least one memory and uses it to encrypt the content, reads the validity determination information from the at least one memory and determines the validity of the content recorded on the cloud server device using the validity determination information.

[0008] A terminal device according to one aspect of the present disclosure is a terminal device used in a recording and playback system, the recording and playback system includes a cloud server device, a recording device that receives and encrypts distributed content and records the encrypted content to the cloud server device via the internet, and the terminal device that plays back the content, the terminal device comprising a circuit and a memory connected to the circuit, the circuit using the memory to perform device authentication with the recording device, obtain an encrypted content key from the recording device, decrypt the content key using a shared key shared between the recording device and the terminal device, access the cloud server device without going through the recording device, read the content recorded and encrypted on the cloud server device, decrypt the read content using the content key and play it back.

[0009] These comprehensive or specific embodiments may be implemented as devices, methods, integrated circuits, computer programs, or recording media such as computer-readable CD-ROMs, or as any combination of devices, methods, integrated circuits, computer programs, and recording media. Furthermore, the recording media may be non-temporary recording media. [Effects of the Invention]

[0010] The terminal device disclosed herein can effectively suppress unauthorized activity related to content.

[0011] Further advantages and effects of one aspect of this disclosure will be made apparent from the specification and drawings. Such advantages and / or effects are provided by several embodiments and configurations described in the specification and drawings, but not all configurations are necessarily required. [Brief explanation of the drawing]

[0012] [Figure 1] Figure 1 shows an example of the configuration of a recording and playback system in an embodiment. [Figure 2]Figure 2 is a simplified diagram showing the configuration of the recording and playback system in the embodiment. [Figure 3] Figure 3 shows an example of the information held by the master unit and management server of the recording and playback system in the embodiment. [Figure 4] Figure 4 shows an example of the configuration of the management server and the information it possesses in the embodiment. [Figure 5] Figure 5 shows an example of the configuration of the master unit and the information it possesses in this embodiment. [Figure 6] Figure 6 shows another example of the information held by the master unit in the embodiment. [Figure 7] Figure 7 is a diagram illustrating the transfer of master control in the embodiment. [Figure 8] Figure 8 shows an example of a data structure including content and management information in an embodiment. [Figure 9] Figure 9 is a sequence diagram showing an example of the processing operation in the recording and playback system when an account is created on the management server and the master unit is registered in the embodiment. [Figure 10] Figure 10 is a sequence diagram showing an example of the processing operation in the recording and playback system when a cloud account is created on the cloud server in the embodiment. [Figure 11] Figure 11 is a sequence diagram showing an example of the processing operation in a recording and playback system when the master unit and the cloud service are linked in an embodiment. [Figure 12] Figure 12 is a sequence diagram showing another example of the processing operation in the recording and playback system when the master unit and the cloud service are linked in the embodiment. [Figure 13] Figure 13 is a sequence diagram showing an example of the processing operation in the recording and playback system when a slave unit is registered and linked to the master unit in the embodiment. [Figure 14]FIG. 14 is a sequence diagram showing an example of the processing operation in the recording and playback system when the master device records content in the cloud service in the embodiment. [Figure 15] FIG. 15 is a sequence diagram showing an example of the processing operation in the recording and playback system when the master device plays back content in the cloud service in the embodiment. [Figure 16] FIG. 16 is a sequence diagram showing an example of the first processing operation among the processing operations in the recording and playback system when the slave device plays back content in the cloud service in the embodiment. [Figure 17] FIG. 17 is a sequence diagram showing an example of the second processing operation among the processing operations in the recording and playback system when the slave device plays back content in the cloud service in the embodiment. [Figure 18] FIG. 18 is a sequence diagram showing an example of the processing operation in the recording and playback system when the master device dubbs content in the cloud service in the embodiment. [Figure 19] FIG. 19 is a sequence diagram showing an example of the processing operation in the recording and playback system when the slave device deletes its own registration in the embodiment. [Figure 20] FIG. 20 is a sequence diagram showing an example of the processing operation in the recording and playback system when the slave device deletes the registration of another slave device in the embodiment. [Figure 21] FIG. 21 is a sequence diagram showing an example of the first processing operation included in the processing operation in the recording and playback system when the slave device changes the cloud service in the embodiment. [Figure 22] FIG. 22 is a sequence diagram showing an example of the second processing operation among the processing operations in the recording and playback system when the slave device changes the cloud service in the embodiment. [Figure 23] FIG. 23 is a sequence diagram showing an example of the first processing operation among the processing operations in the recording and playback system when the transfer of the master device's rights is performed in the embodiment. [Figure 24]Figure 24 is a sequence diagram showing an example of the second processing operation among the processing operations of the recording and playback system when the master control is transferred in the embodiment. [Figure 25] Figure 25 is a sequence diagram showing an example of the processing operation in the recording and playback system when the master unit is transferred in the embodiment. [Modes for carrying out the invention]

[0013] A terminal device according to one aspect of this disclosure is a terminal device used in a recording and playback system, the recording and playback system includes a cloud server device, a recording device that receives and encrypts distributed content and records the encrypted content to the cloud server device via the internet, and the terminal device that plays back the content, the terminal device comprising a circuit and a memory connected to the circuit, the circuit using the memory to perform device authentication with the recording device, obtain an encrypted content key from the recording device, decrypt the content key using a shared key shared between the recording device and the terminal device, access the cloud server device without going through the recording device, read the content recorded and encrypted on the cloud server device, decrypt the read content using the content key and play it back. The terminal device, recording device, and cloud server device are also referred to as a slave device, a master device, and a cloud server, respectively.

[0014] This ensures that even when a recording device records content to a cloud server, when a terminal device directly plays content from the cloud server, it is possible to fully protect the content, guarantee the scope of private use, and provide users with free playback functionality. For example, it is possible to suppress playback of content from the cloud server by any terminal. Therefore, unauthorized activities related to content can be appropriately suppressed, and appropriate access control for client devices can be achieved.

[0015] Furthermore, the circuit may obtain the shared key transmitted from the management server device to the terminal device and the recording device by performing device authentication with the recording device via the management server device.

[0016] This allows the shared key to be shared between the terminal device and the recording device through device authentication, thereby increasing security.

[0017] Furthermore, a recording management system according to one aspect of the present disclosure is a recording management system used in a recording playback system, wherein the recording playback system includes a cloud server device, a recording management system that receives and encrypts distributed content and records the encrypted content to the cloud server device via the Internet, and a terminal device that plays back the content, wherein the recording management system comprises a circuit and at least one memory, the at least one memory holding validity determination information and a content key associated with the cloud server device, the circuit reads the content key from the at least one memory and uses it to encrypt the content, reads the validity determination information from the at least one memory and determines the validity of the content recorded on the cloud server device using the validity determination information. For example, the recording management system comprises a recording device that records the content to the cloud server device and a management server device connected to the recording device via the Internet, wherein the circuit and the at least one memory may each be provided in the recording device or the management server device. Furthermore, the validity determination information may also be information indicating at least one of the following: a checksum for the content management information, a hash value, and the number of times the content has been dubbed. The terminal device, recording device, cloud server device, and management server device are also referred to as the slave device, master device, cloud server, and management server, respectively.

[0018] As a result, information related to content protection, such as validity determination information or content keys, is managed in at least one memory location within the recording management system—an area inaccessible to unspecified users—in addition to the cloud server device, and is linked to the cloud server device. Therefore, because the validity determination information (such as the checksum, hash value, and number of copies per program) and content keys linked to the cloud server device are managed in the recording management system, i.e., the master unit or management server, even if unauthorized copies of content are created, they will be treated as invalid and cannot be played back. In other words, appropriate measures against unauthorized copying on the cloud service can be implemented. Therefore, unauthorized activities related to content can be appropriately suppressed.

[0019] Furthermore, if the management information is maintained and updated in both the recording management system and the cloud server device, the circuit may determine the validity of the content recorded on the cloud server device by comparing the validity determination information obtained from the management information of the recording management system with the validity determination information obtained from the management information of the cloud server device.

[0020] This allows the validity determination information of the recording management system to be compared with the validity determination information of the cloud server device. For example, if they differ, the content is determined to be invalid. As a result, the validity of the content can be appropriately determined.

[0021] Furthermore, a management server device according to one aspect of this disclosure is a management server device used in a recording and playback system, the recording and playback system includes a cloud server device, a first recording device that receives and encrypts distributed content and records the encrypted content to the cloud server device via the Internet, a terminal device that plays back the content, and the management server device connected to the first recording device via the Internet, the management server device comprising a circuit and a memory connected to the circuit, the memory holding first identification information for identifying the first recording device in association with the cloud server device, the circuit replacing the first identification information held in the memory in association with the cloud server device with second identification information for identifying the second recording device when the first recording device is replaced with a second recording device, and transferring protection information held in the first recording device used to protect the content to the second recording device. Note that the terminal device, recording device, and cloud server device are also referred to as the slave device, master device, and cloud server, respectively. Furthermore, the protection information indicates, for example, a content key, a checksum or hash value of management information, the number of copies, etc.

[0022] As a result, when the first recording device is replaced with the second recording device, the first identification information of the first recording device associated with the cloud server device is replaced with the second identification information of the second recording device. In other words, the access rights (also called master rights) to the content of the cloud server device are transferred to the second recording device. Furthermore, the protection information held in the first recording device is transferred to the second recording device. Consequently, the master device migration, that is, the transfer of master rights from the first recording device to the second recording device, can be performed easily and efficiently while adequately protecting the content. Therefore, unauthorized activities related to the content can be appropriately suppressed. Moreover, such migration is considered to be within the scope of personal use and does not exceed the realm of private use. In short, it is possible to achieve appropriate master device migration.

[0023] Furthermore, if the first recording device is removed from the recording and playback system, the circuit may perform at least one of the following: (a) delete the content recorded on the cloud server device by the first recording device; (b) delete the cloud account information for accessing the cloud server device held in the first recording device or the memory; and (c) delete the first identification information held in the memory in association with the cloud account information.

[0024] This process deletes content recorded on the cloud server device and deletes (or resets) cloud account information. Once the cloud account information recorded on the first recording device or management server device is deleted (or reset), the first recording device will no longer be able to access the cloud server device. Therefore, unauthorized access to the cloud server device by the transferred first recording device can be sufficiently prevented, and the proper transfer of the first recording device, i.e., the master unit, can be easily achieved.

[0025] Furthermore, the protection information includes information indicating at least one of the following: a content key for decrypting the content, a checksum for the management information of the content, a hash value, and the number of times the content has been copied.

[0026] This transfers the protection information used to effectively protect the content from the first recording device to the second recording device, thereby increasing security and enabling a proper migration of the master unit.

[0027] The embodiments will be described in detail below with reference to the drawings.

[0028] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, arrangement and connection configurations of components, steps, and the order of steps shown in the following embodiments are examples only and are not intended to limit this disclosure. Furthermore, among the components in the following embodiments, those not described in the independent claim representing the highest-level concept will be described as optional components.

[0029] Furthermore, each figure is a schematic diagram and not necessarily a strictly accurate representation. Also, the same component is denoted by the same reference numeral in each figure.

[0030] (Embodiment) Figure 1 shows an example of the configuration of the recording and playback system in this embodiment.

[0031] In this embodiment, the recording and playback system 100 comprises a master unit 10, a cloud server 20, slave units 31, 32, 33, and a management server 40. Although Figure 1 shows the recording and playback system 100 equipped with slave units 31-33, it may be equipped with only one slave unit. Alternatively, the recording and playback system 100 may be equipped with multiple master units 10.

[0032] The master unit 10 is configured as a receiver or recording device that receives content such as programs distributed via digital broadcasting. The master unit 10 encrypts the received content using the content key Kc and records it to the cloud server 20 via the internet.

[0033] The cloud server 20 provides cloud services to devices that access the cloud server 20 via the internet. The cloud service stores encrypted content recorded by the master unit 10 and transmits that content to the aforementioned devices. The cloud server 20 may also be called a cloud recording server or cloud server device.

[0034] Each of the slave units 31-33 is a terminal device that accesses the cloud server 20 via the internet, receives content stored on the cloud server 20, and plays it back. Note that each of the slave units 31-33 may be collectively referred to as slave unit 30.

[0035] The management server 40 manages the child devices 31-33 and the shared key Kp that is shared between the master unit 10 and each of the child devices 31-33. The shared key Kp is also called a common key or shared key.

[0036] The main unit 10 is installed, for example, inside the home, and the main unit 10 and the slave units 31-33 are connected by a home network.

[0037] In such a recording and playback system 100, the following processes are specifically performed.

[0038] For example, the management server 40 accepts new user registrations and cloud server 20 registrations from the child devices 33 via the internet. Furthermore, the management server 40 manages the association between the child devices 31-33 and the master device 10. In addition, the management server 40 manages the transfer of master device rights. Transfer of master device rights is the process of transferring the master device rights, which are the function or role of the master device 10 that accesses the cloud server 20, from the original recording device to the destination recording device. Only the recording device that possesses these master device rights functions as the master device 10 that accesses the cloud server 20. Note that, below, both recording devices that possess master device rights and recording devices that do not possess master device rights may be referred to as the master device 10.

[0039] Furthermore, the management server 40 issues a shared key Kp to both the master unit 10 and each of the child units 31-33. For example, the management server 40 sends the shared key Kp, which is shared between the master unit 10 and child unit 32, and the cloud server login information required to access the cloud server 20 to the master unit 10 and child unit 32. The cloud server login information includes, for example, the cloud account name and cloud password, as described later.

[0040] When the master unit 10 records content to the cloud server 20 (i.e., the cloud service), it encrypts the content using the content key Kc and records the encrypted content to the cloud service. In Figure 1, the master unit 10 is shown recording content to the cloud server 20 directly via the network, but it is also possible to record content to the cloud service via the smartphone by using the smartphone as a network router (i.e., a bridge), so that the smartphone absorbs the specification differences (i.e., differences) for each cloud service. This means that each time a supported cloud service is added, it is not necessary to change the embedded software of the master unit 10, and it is possible to handle it with only a software update on the smartphone side. Since the master unit 10 always only accesses the smartphone, it does not need to know information about the cloud service.

[0041] Furthermore, the master unit 10 encrypts the content key Kc using the shared key Kp and transmits the encrypted content key Kc to the slave unit 32 via the internet.

[0042] The child device 32 is registered in the management server 40 as a device linked to the parent device 10. The child device 32 then requests content playback from the parent device 10. In response to this playback request, the child device 32 obtains the content key Kc, which is encrypted with the shared key Kp, from the parent device 10. The child device 32 decrypts the content key Kc using the shared key Kp. The child device 32 then accesses and logs into the cloud server 20 registered in the management server 40 and obtains the content stored in the cloud server 20. Furthermore, the child device 32 decrypts and plays the content using the content key Kc. In other words, the child device 32 decodes the stream.

[0043] Furthermore, if the master unit 10 used in the recording and playback system 100 is replaced with another recording device, that is, if the master unit rights are transferred, for example, the slave unit 33 registers the new master unit with the management server 40. The master unit 10 transfers the content key Kc and cloud server login information to the new master unit. Then, the master unit 10 deletes the content key Kc and other information.

[0044] Furthermore, the slave unit 31 is located, for example, within the home and meets the cloud usage requirements. These cloud usage requirements are those stipulated for playing content recorded on a cloud service, and they define what is required of the slave unit and the master unit (including the management server). In other words, the slave unit 31 can access the cloud server 20 via the internet and retrieve and play the content stored on the cloud server 20. Also, the slave unit 32 is located, for example, outside the home and meets the remote viewing requirements. These remote viewing requirements are, for example, those specified in the ARIB standard, Terrestrial Digital Television Broadcasting Operation Regulations ARIB TR-B14, Part 5, Appendix C, Remote Viewing Requirements for Digital Broadcast Receivers. Moreover, the slave unit 32 also meets the aforementioned cloud usage requirements. In other words, the slave unit 32 can access the master unit 10, and if content is stored on the master unit 10, it can retrieve and play that content. Furthermore, it can access the cloud server 20 via the internet and play the content stored on the cloud server 20.

[0045] Figure 1 illustrates an example of a system including a management server 40. However, as shown in Figure 5 later, it is also possible to have the functions of the management server 40 on the master unit 10, or to have some or all of the functions of the management server 40 on the child device 30, such as a smartphone. If the functions of the management server 40 are on the child device 30, the master unit 10 will obtain information about the cloud service from the child device 30 and access the cloud server 20, as in the example above. However, when the child device 30 accesses the cloud server 20, the information is contained within the child device 30, so no information is obtained externally. Therefore, this is suitable for playing content on the cloud server 20 from the child device 30. On the other hand, if there are multiple child devices 30, information cannot be shared, and each child device 30 must maintain its own information about the cloud service, which becomes a challenge. On the other hand, not having a management server 40 offers significant advantages in terms of system load, and may therefore be considered as one aspect of this disclosure.

[0046] Figure 2 is a simplified diagram showing the configuration of the recording and playback system 100 in this embodiment.

[0047] As shown in Figure 2, the master unit 10 is, for example, a recording device placed in a home, which receives content such as programs, which are digital data distributed by broadcast. The master unit 10 may output the received content as video and audio to a television receiver, or it may store it on a recording medium. In this embodiment, the master unit 10 is connected to a cloud server 20, a slave unit 30, and a management server 40 via the internet. The cloud server 20 may also be called a general-purpose cloud service. The slave unit 30 may be any one of the slave units 31 to 33 shown in Figure 1, or it may be a collection of multiple slave units.

[0048] In this embodiment, the content is distributed by broadcast, but it may also be distributed via the internet.

[0049] Figure 3 shows an example of the information held by the master unit 10 and the management server 40 of the recording and playback system 100.

[0050] The master unit 10 stores information such as the number of times the content has been dubbed, the checksum of the content's management information, and the content key Kc. For example, this information is stored in the memory provided by the master unit 10.

[0051] The number of copies refers to the number of times content recorded on the cloud server 20 can be copied.

[0052] The management information checksum is a checksum of the management information, which is information used to manage the content recorded on the cloud server 20. For example, if one or more contents are recorded according to the BDAV (Blu-ray® Disc Audio / Visual) standard, the management information checksum is used to determine the validity of BDAV on the cloud server 20. In other words, the checksum is used to determine the validity of a group of contents (i.e., the entire disc) recorded according to the BDAV standard. The checksum is also called the management information checksum. A specific example of management information is shown in Figure 8. Furthermore, the number of times each content has been dubbed is also used to determine the validity of that content.

[0053] The content key Kc is used to encrypt and decrypt content recorded on the cloud server 20.

[0054] The management server 40 maintains a management list as information. For example, the management list is stored in the memory of the management server 40. This management list is a list for managing the master unit 10, the slave unit 30, and the cloud server 20, and includes, for example, the account list L1, the slave unit list L3, the cloud service list L4, the master unit list L5, etc., as shown in Figure 4.

[0055] Figure 4 shows an example of the configuration of the management server 40 and the information it possesses.

[0056] The management server 40 comprises an account management unit 41, a shared key management unit 42, a child device management unit 43, a cloud service account management unit 44, and a master device management unit 45.

[0057] The account management unit 41 manages an account list L1 that shows the account information L2 for one or more users. The account list L1 has, for example, the account information L2 of one user. The account information L2 includes the user's account name and password pair, and a master-slave unit association list. The master-slave unit association list shows one or more master-slave unit set information, and that master-slave unit set information shows a pair consisting of a master unit ID, a slave unit ID, a shared key ID, and an expiration date. In other words, each pair shown in the master-slave unit association list is associated with a master unit ID, a slave unit ID, a shared key ID, and an expiration date.

[0058] The master unit ID is the identification information for master unit 10, and the slave unit ID is the identification information for slave unit 30. The shared key ID is the information associated with the shared key, and is the identification information for the shared key shared between master unit 10 (associated with the master unit ID) and slave unit 30 (associated with the slave unit ID). The expiration date is the authentication expiration date for slave unit 30 corresponding to the slave unit ID associated with that expiration date.

[0059] Each pair shown in this master-slave pairing list displays the identification information of the authenticated master unit 10 and slave unit 30. Therefore, it can be said that the account management unit 41 manages the device authentication relationship between the master unit 10 and the slave unit 30 using the account information L2 shown in the account list L1.

[0060] The master unit IDs shown for each group may be different from each other, or they may be the same. Also, the number of slave unit IDs included in each group is not limited to one, but may be multiple.

[0061] The shared key management unit 42 manages one or more shared keys Kp. Specifically, for each account information L2 included in the account list L1, the shared key management unit 42 manages a shared key Kp corresponding to each of the one or more shared key IDs indicated in that account information L2.

[0062] In the example shown in Figure 4, the expiration date is shown in association with the child device ID and shared key ID in the parent-child device association list of account information L2, but it does not have to be shown in the parent-child device association list. In this case, the shared key management unit 42 may manage the expiration date of the child device 30 that has the shared key Kp indicated by the shared key ID for each shared key ID. In other words, the expiration date is managed as the expiration date of the shared key Kp.

[0063] The master unit management unit 45 manages a master unit list L5 that shows information about one or more master units 10. For each of the one or more master units 10 registered in the home network, the master unit list L5 shows the master unit ID, IP (Internet Protocol) address, and master unit password of that master unit 10.

[0064] The sub-unit management unit 43 manages a sub-unit list L3 that shows information about one or more sub-units 30. For each of the one or more sub-units 30 registered in the home network, the sub-unit list L3 shows the sub-unit ID and the IP (Internet Protocol) address of that sub-unit 30.

[0065] The Cloud Service Account Management Unit 44 manages the Cloud Service List L4, which shows the relationship between the master unit 10 and the cloud service. The Cloud Service List L4 shows, for each cloud service, information about that cloud service and information about the master unit 10 linked together. The information about the cloud service includes the Cloud Service ID, which is the identification information of the cloud service, the URL (Uniform Resource Locator) that indicates the location of the cloud service, and the cloud account name and cloud password required to use the cloud service. The information about the master unit 10 includes the master unit ID and master unit password.

[0066] In the aforementioned transfer of master unit rights, the Cloud Service Account Management Unit 44 updates the master unit ID in the Cloud Service List L4. Furthermore, when a cloud service is deleted or migrated, the Cloud Service Account Management Unit 44 also updates this Cloud Service List L4.

[0067] In the example in Figure 4, the management server 40 holds a management list that includes the account list L1 and the child device list L3, but the master device 10 may also hold the management list.

[0068] Figure 5 shows an example of the configuration of the master unit 10 and the information it possesses.

[0069] If the master unit 10 has a management list, the master unit 10 is equipped with an account management unit 41, a shared key management unit 42, a slave unit management unit 43, and a cloud service account management unit 44 instead of the management server 40. In this case, the management list does not contain information about the master unit 10. Also, as shown in the example in Figure 5, if the master unit 10 has a management list, it can be said that the master unit 10 has the functions of the management server 40. Therefore, in such cases, the recording and playback system 100 does not need to be equipped with a management server 40.

[0070] In the example shown in Figure 5, the master unit 10 is a multi-user compatible device, and the account management unit 41 manages an account list L1 that shows the account information L2 of multiple users. On the other hand, the master unit 10 may also be a single-user compatible device. In this case, the management server 40 directly manages one account information L2 without having an account management unit 41 or an account list L1.

[0071] Furthermore, in the example shown in Figure 5, the master unit 10 manages the shared key Kp, and when the slave unit 30 authenticates the slave unit, the shared key Kp is provided to the slave unit 30 and is available for use until its expiration date.

[0072] Figure 6 shows another example of the information held by the master unit 10.

[0073] As shown in Figure 6, the master unit 10 has cloud service information L11 or L12, which is information about the cloud services that the master unit 10 has registered. Such cloud service information L11 or L12 is stored in the memory of the master unit 10. Cloud service information L11 indicates the cloud service ID, URL, cloud account name, and cloud password of the cloud services that the master unit 10 has registered.

[0074] On the other hand, the cloud service information L12 indicates the cloud service ID of the cloud service registered by the master unit 10, but does not indicate the URL, cloud account name, or cloud password. In the example shown in Figures 9 to 25 of this embodiment, the master unit 10 has cloud service information L12 instead of cloud service information L11, and performs processing using that cloud service information L12. In this case, when the master unit 10 and the slave unit 30 access the cloud service, they need to obtain the cloud service URL, cloud account name, and cloud password from the management server 40 each time.

[0075] Furthermore, the master unit 10 holds content-related information L13, which indicates the number of dubbings, the checksum of the management information, and the content key Kc. Specifically, the content-related information L13 indicates the cloud service ID, the management information checksum associated with the cloud service indicated by that cloud service ID, and the program management list of that cloud service.

[0076] The program management list shows, for each program recorded on the cloud service, the program ID (which is the program's identification information), the number of times the program has been dubbed, and the content key Kc for the program. The program ID may be, for example, the filename of the rpls file shown in Figure 8 below, consisting of a 5-digit number.

[0077] Furthermore, while Figure 6 shows that the master unit 10 holds content-related information L13, it is also possible that the management server 40 holds all or part of this information. By having the management server 40 hold this information, the content-related information L13 can be obtained from the management server 40 regardless of the power status (on / off) of the master unit 10, and playback can be directly performed from the cloud service 20 even when the master unit 10 is powered off.

[0078] Figure 7 is a diagram illustrating the transfer of master unit rights.

[0079] During the transfer of master unit rights, the management server 40 rewrites the master unit ID and master unit password shown in the cloud service list L4. At that time, the original master unit 10 (recording device) and the destination recording device (newly designated as master unit 10) transfer the number of copies managed by the original master unit 10, the content key Kc, and the management information checksum. The transfer of master unit rights is completed when both the rewriting on the management server 40 and the transfer between the recording devices are performed.

[0080] Furthermore, if the management server 40 functionality is provided in the master unit 10, that is, if the recording and playback system 100 does not have a management server 40, then, as shown in Figure 5, the cloud service list L4 exists in the master unit 10. Therefore, in addition to the number of copies, content key Kc, and management information checksum, the cloud service list L4 is also transferred between recording devices. However, in such an example, there is a security vulnerability because the master unit rights could be illegally duplicated if the user turns off the power during the transfer process. Therefore, a configuration in which the recording and playback system 100 has a management server 40 separate from the master unit 10 can be made more secure than a configuration in which the master unit 10 has the management server 40 functionality.

[0081] Furthermore, when transferring ownership of the master unit, the shared key Kp and the device authentication status of the slave unit 30 may also be transferred between the recording devices. However, regarding device authentication, since the slave unit 30 also retains the information of the master unit 10, the transfer cannot be completed by processing only the master unit 10 and the management server 40. Therefore, the transfer of the shared key Kp and the device authentication status of the slave unit 30 may not be performed, and the new master unit 10 may restart the process from device authentication of the slave unit 30. In this case, the security level can be increased compared to when the transfer is performed.

[0082] Figure 8 shows an example of a data structure that includes content and management information.

[0083] For example, cloud server 20 stores one or more content items according to the BDAV standard data structure, as shown in Figure 8. In this data structure, there is a BDAV directory in the root directory. The BDAV directory is the original directory of the BDAV standard. This BDAV directory contains the file "Info.bdav", a PLAYLIST directory, a CLIPINF directory, and a STREAM directory.

[0084] The file "Info.bdav" contains the overall management information for the BDAV directory and its subdirectories, including a program list (i.e., a program catalog). For example, the checksum or hash value of this file "Info.bdav" is used to determine the validity of the entire BDAV directory (i.e., the entire disc mentioned above). In other words, an example of the management information checksum mentioned above is the checksum of the file "Info.bdav".

[0085] The PLAYLIST directory contains rpls files such as "00001.rpls". These rpls files provide detailed information such as the program name and also indicate the playback order (scenario) of the clpi files contained in the CLIPINF directory.

[0086] The CLIPINF directory contains clpi files such as "00100.clpi". clpi files contain content management information, including audio / video attribute information and a playback map table. If the content key Kc is managed within the BDAV standard, it is managed using this clpi file. Content is also referred to as a stream, stream data, or stream file.

[0087] Normally, immediately after recording content, there is a one-to-one relationship between the files in the PLAYLIST directory and the files in the CLIPINF directory related to that content. When programs are merged, one program (i.e., a file in the PLAYLIST directory) may reference multiple files in the CLIPINF directory. Conversely, when programs are split, multiple files in the PLAYLIST directory may reference (or share) a single file in the CLIPINF directory. Note that during program merging and splitting, the files in the CLIPINF directory and the STREAM directory remain unchanged; only the files in the PLAYLIST directory are modified. Program merging and splitting are performed in accordance with the BDAV standard.

[0088] The STREAM directory contains m2ts files such as "00100.m2ts". These m2ts files are stream data corresponding to the content. At a minimum, these m2ts files are required for content playback. Furthermore, of the data structure shown in Figure 8, at least the STREAM directory containing the m2ts files must be located on the cloud service. Also, there is a one-to-one relationship between the files in the CLIPINF directory and the files in the STREAM directory. Note that while we've used M2TS here as an example since we're using an MPEG2 Transport stream, when recording 4K broadcasts, MMT / TLV streams are recorded, resulting in MMTS files. The file names differ depending on the container storing the stream, but they all indicate where the stream is recorded.

[0089] Here, the validity of the content is determined on the master unit 10, which cannot be operated by the user. The validity of the content on the cloud server 20 is determined by at least one of the first and second determination methods.

[0090] The first determination method utilizes the checksum or hash value of the management information. For example, if content is recorded on the cloud server 20 in accordance with the structure of the BDAV standard's management information, there is an "info.bdav" file that manages the entire disc. By constantly updating the checksum of this file and synchronizing it between the cloud server 20 and the master unit 10, the validity of the entire disc can be determined. In other words, the master unit 10 and the cloud server 20 repeatedly synchronize and perform checksum updates of the "info.bdav" file. The master unit 10 determines that all content managed by the "info.bdav" file on the cloud server 20 contains invalid content if the checksum updated on the master unit 10 differs from the checksum updated on the cloud server 20. In this case, the number of dubbing attempts may be retained on the cloud server 20.

[0091] In the second determination method, the master unit 10 manages the number of times each program has been dubbed. Each time content is dubbed, the master unit 10 decreases the number of dubs for that content by one. When the number of dubs eventually reaches zero, the master unit 10 deletes the entry for that program from its program management list. This prevents dubs from exceeding a specified number, even if a copy of a legitimate program is illegally created, and the legitimate program is repeatedly dubbed, replacing the legitimate program on the cloud server 20 with the copy.

[0092] With the second determination method alone, the number of copies is checked at the moment processing is actually performed on the content, and the content is determined to be invalid based on that number of copies. Therefore, the user is informed that the program is invalid only after they have gone to the trouble of selecting it. On the other hand, with the first determination method, it is possible to determine whether the disc is valid or invalid the moment the disc (i.e., the BDAV directory) is accessed, so a warning panel can be displayed to the user very quickly.

[0093] Furthermore, in this embodiment, the cloud server 20 stores content in a manner compliant with the BDAV standard, so that the slave device 30 can also directly access the cloud server 20 and play the content. In other words, the cloud server 20 stores not only the content but also the management information for that content. Therefore, if the slave device 30 obtains the content key Kc from the master device 10 using application software (also called a viewing app) that can interpret the BDAV standard, it can perform playback processing, including the interpretation of the BDAV standard management information stored in the cloud server 20, within the slave device 30. However, in this embodiment, the interpretation of the management information is basically performed by the master device 10. However, if the slave device 30 implements a viewing app that interprets the management information as described above, the playback processing including that interpretation may be confined to the slave device 30.

[0094] On the other hand, in order to minimize the amount of information stored on the cloud server 20, only the content, which is stream data, may be stored on the cloud server 20, and the master unit 10 may hold other management information. Alternatively, the management information may be stored on the management server 40 instead of the master unit 10. In this case, if the management server 40 stores up to the content key Kc, it becomes possible to achieve playback from the slave unit 30 completely independently of the device state of the master unit 10.

[0095] In this case, displaying the content list (i.e., the program list), selecting the program to be played, and determining the playback position are all achieved by the slave unit 30 querying the master unit 10. The slave unit 30 obtains the URL of the stream data (i.e., the URL of the cloud service that provides the stream data) from the master unit 10, and finally, it obtains only the content, which is the stream data to be played, by accessing the cloud server 20. In the case of remote viewing, the master unit 10 decrypts the stream data, protects it with DTCP (Digital Transmission Content Protection) (i.e., encrypts it), and delivers it to the slave unit 30.

[0096] Furthermore, the method for determining the validity of the content may differ between Case 1, where the management information is stored on the cloud server 20, and Case 2, where the management information is stored on the master unit 10. In Case 1, validity is determined using the number of copies and checksums, etc. On the other hand, in Case 2, since all BDAV management information other than the stream data is on the master unit 10, such validity determination using checksums may not be necessary.

[0097] In this embodiment, the BDAV standard data structure is used as an example of a data structure. However, in this embodiment, any data structure that includes a content list, management information for individual content, and a stream file may be used, not limited to the BDAV standard data structure.

[0098] Figure 9 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when an account is created on the management server 40 and the master unit 10 is registered.

[0099] First, the child device 30, which may be a personal computer (also called a PC) or a smartphone (also called a mobile phone), accesses the management server 40 (step S1). Then, the child device 30 requests account creation from the management server 40 by specifying an account name and password, and logs in (step S2).

[0100] The management server 40 adds new account information L2 to the account list L1 and records the specified account name and password in that account information L2 (step S3).

[0101] Meanwhile, each of the one or more master units 10 configures the home network and sets a master unit password, for example, in response to user input (step S15). In other words, each of the one or more master units 10 is connected to the home network and holds a device name, IP address, and master unit password. The device name is set by the user, but it may instead be a uniquely determined master unit ID.

[0102] The child unit 30 searches for each of the one or more master units 10 connected to the home network as a candidate for the master unit 10 to be registered (step S4). In other words, the child unit 30 obtains the device name and IP address of each of the one or more master units 10 connected to the home network (step S5). The child unit 30 then displays a list of the one or more master units 10 connected to the home network as a master unit candidate list (step S6). The master unit candidate list shows, for example, the device name and IP address of each of the one or more master units 10 mentioned above. In response to the user's registration operation, the child unit 30 determines the master unit 10 to be registered from the master unit candidate list (step S7). The child unit 30 then attempts to log in to the determined master unit 10 by entering the master unit password (step S8).

[0103] The child device 30 determines whether the login was successful based on the processing in step S8 (step S9). If the child device 30 determines that the login was unsuccessful (No in step S9), it terminates the process for registering with the parent device 10. On the other hand, if the child device 30 determines that the login was successful (Yes in step S9), it logs out of the parent device 10 that it logged into in step S8 (step S10). Furthermore, the child device 30 requests the management server 40 to register it in the parent device list L5 held by the management server 40, that is, to register the parent device ID, IP address, and parent device password of the parent device 10 determined in step S7 (step S11). In response to the request from the child device 30, the management server 40 registers the parent device ID, IP address, and parent device password in the parent device list L5 (step S12).

[0104] Next, the child device 30 requests the management server 40 to register the parent device 10 in account information L2, specifying the parent device ID and parent device password determined in step S7 (step S13). In response to the request from the child device 30, the management server 40 registers the parent device 10 determined in step S7 in account information L2 as a parent device 10 that can access the cloud server 20. That is, the management server 40 registers the parent device ID specified by the child device 30 in account information L2 (step S14).

[0105] Figure 10 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when a cloud account is created on the cloud server 20.

[0106] First, the child device 30, which may be a PC or smartphone, requests the management server 40 to perform cloud service registration processing (step S21). In response to the request from the child device 30, the management server 40 requests the child device 30 to input the information necessary for cloud service registration processing (step S22).

[0107] The slave unit 30 accepts input from the user, for example, such as the cloud account name, cloud password, email address, and payment information, as input for the cloud service registration process (step S23). The slave unit 30 then sends this information to the management server 40 (step S24).

[0108] When the management server 40 receives the above information from the slave device 30, it sends that information to the cloud server 20 and requests the cloud server 20 to create a cloud account (step S25). The cloud server 20 checks the information (i.e., the input information) and creates a cloud account according to the content of that information (step S26). Then, the cloud server 20 notifies the management server 40 that the cloud account creation is complete and provides the access URL (step S27).

[0109] The management server 40 adds a new cloud service ID to the cloud service list L4 that corresponds to the cloud account created by the cloud server 20. Furthermore, the management server 40 registers the access URL (i.e., URL) notified by the cloud server 20 in the cloud service list L4, associating it with the cloud service ID. In addition, the management server 40 registers the cloud account name and cloud password indicated by the information sent from the child device 30 in the cloud service list L4, associating them with the cloud service ID (step S28).

[0110] Then, the management server 40 notifies the child device 30 that the cloud account creation is complete and provides the cloud service ID (step S29).

[0111] Figure 11 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when the master unit 10 is linked to a cloud service. In the example shown in Figure 11, the cloud service ID is recorded in the master unit 10 as a result of this processing operation. In other words, the master unit 10 holds the cloud service information L12 shown in Figure 6.

[0112] First, the slave unit 30 determines the master unit 10 to access the cloud service in response to user input (step S31). Then, the slave unit 30 sets the master unit to access the cloud service by inputting a pair of the cloud service ID corresponding to that cloud service and the master unit ID of the determined master unit 10 to the management server 40 (step S32).

[0113] The management server 40 searches for the entered master unit ID in the master unit list L5 and retrieves the master unit password associated with that master unit ID in the master unit list L5. Furthermore, the management server 40 registers the master unit ID and master unit password in the cloud service list L4, associating them with the cloud service ID entered in step S32 (step S33). This links the master unit 10 with the cloud service.

[0114] Meanwhile, the master unit 10 accepts input from the user (step S34) and starts the cloud recording settings (step S35). Then, the master unit 10 enters the master unit ID into the management server 40 and queries the management server 40 for available cloud services (step S36).

[0115] In response to a query from the master unit 10, the management server 40 searches the cloud service list L4 for an entry with the master unit ID (step S37). In other words, the management server 40 searches the cloud service ID associated with the master unit ID from the cloud service list L4. The management server 40 then sends the retrieved cloud service ID to the master unit 10 (step S38). When the master unit 10 receives the cloud service ID from the management server 40, it adds the cloud service as a recording destination (step S39). In other words, the master unit 10 records the received cloud service ID in the cloud service information L12. In this example shown in Figure 11, when the master unit 10 logs into a cloud service, it queries the management server 40 each time for detailed information about that cloud service (e.g., URL, cloud account name, and cloud password).

[0116] Furthermore, after the processing in step S32, the slave unit 30 logs out from the management server 40 (step S40).

[0117] Figure 12 is a sequence diagram showing another example of the processing operation in the recording and playback system 100 when the master unit 10 is linked to a cloud service. In the example in Figure 12, the processing operation records not only the cloud service ID but also the cloud account name and cloud password in the master unit 10. In other words, the master unit 10 holds the cloud service information L11 shown in Figure 6.

[0118] First, the recording and playback system 100 performs the same processing as steps S31 to S36 shown in Figure 11 (steps S41 to S46).

[0119] Next, in response to a query from the master unit 10, the management server 40 searches the cloud service list L4 for an entry with the master unit ID entered by the master unit 10 (step S47). At this time, the management server 40 searches the cloud service list L4 for the cloud service ID, URL (i.e., cloud URL), cloud account name, and cloud password associated with that master unit ID. The management server 40 then sends the retrieved cloud service ID, URL, cloud account name, and cloud password to the master unit 10 (step S48). When the master unit 10 receives the cloud service ID, etc. from the management server 40, it adds the cloud service as a recording destination (step S49). In other words, the master unit 10 records the received cloud service ID, URL, cloud account name, and cloud password in the cloud service information L11. Note that in this example shown in Figure 12, the master unit 10 does not need to query the management server 40 for detailed information about the cloud service when logging into the cloud service.

[0120] Then, after the processing in step S42, the slave unit 30 logs out from the management server 40 (step S50).

[0121] Figure 13 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when the slave unit 30 is registered and linked to the master unit 10.

[0122] First, for example, a smartphone (device 30) logs in to the management server 40 by entering its account name and password (step S51). Then, the device 30 sends its device ID and IP address to the management server 40 so that the logged-in device 30 is registered (step S52).

[0123] When the management server 40 receives the child ID and IP address from the child device 30, it registers the child ID and IP address in the child device list L3, associating them with each other (step S53). Then, the management server 40 notifies the child device 30 that the registration is complete (step S54).

[0124] When the child unit 30 receives a notification from the management server 40, it obtains the parent unit list L5 from the management server 40 (step S55). Note that the parent unit password is omitted from the parent unit list L5. Then, the child unit 30 determines the parent unit 10 from the parent unit list L5 in response to the user's input (step S56). In other words, the child unit 30 selects the parent unit 10 to be accessed from the one or more parent units 10 shown in the parent unit list L5. Furthermore, the child unit 30 inputs its child unit ID, the parent unit ID and parent unit password of the parent unit 10 determined from the parent unit list L5 to the management server 40 and requests the management server 40 to configure access to that parent unit 10 (step S57).

[0125] The management server 40 determines whether the entered master unit ID and master unit password are correct in response to a request from the slave unit 30 (step S58). In other words, the management server 40 determines whether the master unit ID and master unit password are correct by performing an access check to the master unit 10 using the master unit ID and master unit password. If the master unit ID and master unit password are correct, the management server 40 registers the slave unit 30 and master unit 10 by creating master unit / slave unit set information in account information L2 (step S60). The master unit / slave unit set information is information that associates the master unit ID determined to be correct, the slave unit ID of the slave unit 30 that made the request to the management server 40, the shared key ID, and the expiration date of the shared key Kp. In other words, the management server 40 sets the expiration date, generates the shared key Kp, and assigns the shared key ID to the shared key Kp. Device authentication is performed between the master unit 10 and the slave unit 30 through these steps S57 to S60. Then, the management server 40 notifies the slave unit 30 of the shared key Kp (step S61), and also notifies the master unit 10 associated with the slave unit 30 of the shared key Kp (step S62).

[0126] In the example shown in Figure 13, the shared key Kp is notified to the child unit 30 and the master unit 10 at the timings of steps S61 and S62, but it may be notified at other times. For example, when the content of the cloud service is played, the master unit 10 and the child unit 30 may each specify the master unit ID, child unit ID, and cloud service ID to the management server 40 and request the management server 40 to notify them of the shared key Kp.

[0127] Furthermore, in this embodiment, an access check to the master unit 10 is performed in step S58, but this access check is not required. However, if there is a possibility that the password of the master unit 10 may be changed, it is advisable to perform such an access check.

[0128] Figure 14 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when the master unit 10 records content to a cloud service.

[0129] First, the master unit 10 accepts the user's input and initiates recording to the cloud service (step S65). Next, the master unit 10 logs into the management server 40 using its master unit ID and master unit password and requests the management server 40 to provide the URL of the cloud server 20 (i.e., the cloud service), the cloud account name, and the cloud password (step S66). In response to the request from the master unit 10, the management server 40 notifies the master unit 10 of the URL of the cloud server 20, the cloud account name, and the cloud password (step S67).

[0130] When the master unit 10 receives a notification from the management server 40, it logs out of the management server 40 (step S68) and logs in to the cloud service using the URL, cloud account name, and cloud password (step S69). Furthermore, the master unit 10 requests the cloud server 20 to create management information (step S70). Note that this management information may be various types of information other than the stream file (i.e., m2ts file) from the data structure shown in Figure 8.

[0131] Next, the master unit 10 repeatedly executes the processes in steps S71 to S75 until recording stops. For example, the processes in steps S71 to S75 are executed for each block of broadcast content. Specifically, the master unit 10 analyzes the broadcast content and obtains attribute information, special playback map information, etc. of the content (step S71). The special playback map information is, for example, a management table for each GOP (Group of Pictures) in MPEG2 Video, which manages the address, time code, and IPIC size within the stream file. Similarly, in H.264 and H.265, special playback map information is created each time an IPIC is detected within the stream. Such special playback map information is used for jump playback, special playback, etc., and is also used to derive the starting address during normal playback. Next, the master unit 10 encrypts the stream data, which is the content, using the content key Kc (step S72). The master unit 10 requests the cloud server 20 to write the encrypted stream data (step S73). Furthermore, the master unit 10 updates the management information (step S74) and requests the cloud server 20 to update the management information (step S75).

[0132] Then, when the master unit 10 receives a recording stop command in response to, for example, an input operation by the user (step S76), it requests the cloud server 20 to close the management information (step S77). Furthermore, the master unit 10 requests the cloud server 20 to close the stream data (step S78). Then, the master unit 10 records the content key Kc and the number of dubbings (step S79) and logs out from the cloud server 20 (step S80).

[0133] Figure 15 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when the master unit 10 plays content from a cloud service.

[0134] First, the master unit 10 enters its master unit ID and master unit password into the management server 40 to log in (step S81). Next, the master unit 10 enters its cloud service ID into the management server 40 to obtain the cloud account name, cloud password, and URL associated with that cloud service ID from the management server 40 (step S82). Furthermore, the master unit 10 enters its cloud account name and cloud password into the cloud service indicated by that URL to log in (step S83). Then, the master unit 10 obtains the program list, which is a list of recorded content, from the cloud service (i.e., the cloud server 20) by reading it from the management information (step S84).

[0135] The master unit 10 displays the acquired list of programs, and, for example, in response to user input, selects a program to be played from the list and starts processing to play the content of that program (step S85). In other words, the master unit 10 obtains the management information of the program from the cloud server 20 (step S86) and obtains the stream file name from that management information (step S87). Next, the master unit 10 searches within the cloud service using the stream path and accesses and opens the stream file with the specified stream file name (step S88).

[0136] The master unit 10 then repeatedly executes steps S89 and S90 until playback is stopped. In other words, the master unit 10 reads data from the stream file (i.e., stream data) that is an integer multiple of the size of an encrypted block (step S89). Next, the master unit 10 decrypts the data from the stream file using the content key Kc and decodes the data in GOP units (step S90). Note that the unit of encryption (i.e., encrypted block) and the unit of decoding (i.e., GOP) are different from each other. The unit of encryption is of fixed length, while the unit of decoding is of variable length. Playback is then achieved when the decoding result is output to a monitor screen such as a TV.

[0137] Next, the master unit 10 requests the cloud server 20 to close the stream file (step S91) and logs out of the cloud server 20 (step S92). Furthermore, the master unit 10 logs out of the management server 40 (step S93). Step S93 may be executed at this time, or immediately after step S82.

[0138] Figure 16 is a sequence diagram showing an example of the first processing operation in the recording and playback system 100 when the slave unit 30 plays content from a cloud service.

[0139] First, the child device 30, for example, a smartphone, enters its account name and password into the management server 40 to log in (step S95). Then, the child device 30 enters the parent device ID into the management server 40 and obtains the IP address associated with that parent device ID from the management server 40 (step S96). Next, the child device 30 enters the parent device password into the parent device 10 corresponding to its parent device ID and IP address to log in (step S97). Furthermore, the child device 30 selects the cloud service to be used as the playback destination and specifies that cloud service to the aforementioned parent device 10 (step S98). In this case, if the parent device 10 has multiple cloud services as recording destinations, the cloud services will be displayed in a list alongside the built-in HDD and optical disc, and the user will select the cloud service from among them to play back.

[0140] The master unit 10 enters its master unit ID and master unit password into the management server 40 to log in (step S99). The master unit 10 then enters its own cloud service ID into the management server 40 to retrieve the cloud account name, cloud password, and URL associated with that cloud service ID from the management server 40, and logs out (step S100). The master unit 10 then enters the retrieved cloud account name and cloud password into the cloud server 20 corresponding to the retrieved URL to log in (step S101). The master unit 10 then retrieves the program list from the cloud server 20 by reading the management information (step S102), and provides the aforementioned cloud service ID and program list to the slave unit 30 (step S103).

[0141] The slave unit 30 determines which program to play from the provided list of programs (step S104), specifies the determined program to the master unit 10, and requests the master unit 10 to provide the program's content key Kc and the URL of the stream file (step S105).

[0142] Upon receiving the request, the master unit 10 obtains the program's management information from the cloud server 20 (step S106). Furthermore, the master unit 10 obtains the stream file name from the management information and generates a stream path (step S107). Then, using that stream path, the master unit 10 searches the cloud server 20 for the stream file with the aforementioned stream file name and obtains the URL of that stream file (step S108). Alternatively, the master unit 10 may generate a URL to access the stream file from the URL it uses to access the cloud server 20. Since the procedures for this are likely to differ depending on the cloud service, it is sufficient to obtain information on how to access the stream file in a way that is appropriate for that server.

[0143] Figure 17 is a sequence diagram showing an example of the second processing operation in the recording and playback system 100 when the slave unit 30 plays content from the cloud service. Note that the second processing operation is an operation that continues from the first processing operation.

[0144] After processing in step S108 in Figure 16, the master unit 10 encrypts the content key Kc of the stream file using the shared key Kp (step S110). Furthermore, the master unit 10 provides the encrypted content key Kc and the URL of the stream file to the slave unit 30 (step S111).

[0145] When the child device 30 obtains the encrypted content key Kc, it decrypts the content key Kc using the shared key Kp (step S112). The child device 30 then inputs the cloud service ID provided in step S103 into the management server 40 and requests the management server 40 to provide the cloud account name, cloud password, and URL associated with that cloud service ID (step S113). In response to the request from the child device 30, the management server 40 provides the cloud account name, cloud password, and URL to the child device 30 (step S114).

[0146] The slave device 30 logs into the cloud server 20 corresponding to the provided URL by entering the provided cloud account name and cloud password (step S115). Furthermore, the slave device 30 specifies the URL of the stream file to the cloud server 20 and opens the stream file (step S116). Furthermore, the slave device 30 repeatedly executes steps S117 and S118 until playback is stopped. In other words, the slave device 30 reads data from the stream file (i.e., stream data) that is an integer multiple of the size of the encrypted block (step S117). Next, the slave device 30 decrypts the data from the stream file using the content key Kc and decodes the data in GOP units (step S118). The result of this decoding is displayed on the output device equipped with the slave device 30 to realize playback.

[0147] Furthermore, the child device 30 closes the stream file on the cloud server 20 (step S119). Subsequently, the child device 30 logs out of the cloud server 20 (step S120) and logs out of the parent device 10 (step S121). As a result, the parent device 10 logs out of the cloud server 20 (step S122). Then, the child device 30 also logs out of the management server 40 (step S123).

[0148] In the example shown in Figure 17, a login is performed in step S115, but this login can be omitted. If the cloud server 20 is configured to be accessible to anyone, a login is not necessary. In some cases, it may be possible to access the file immediately in READ ONLY mode via URL, and in such cases, the login can be omitted.

[0149] Figure 18 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when the master unit 10 dubs content from a cloud service.

[0150] First, the master unit 10 selects a disk on the cloud server 20 as the target for dubbing, for example, in response to input from the user (step S125). Next, the master unit 10 enters its master unit ID and master unit password into the management server 40 and logs in (step S126). Furthermore, the master unit 10 enters its cloud service ID into the management server 40 and retrieves the cloud account name, cloud password, and URL associated with that cloud service ID from the management server 40 (step S127), and logs out from the management server 40 (step S128).

[0151] Next, the master unit 10 logs in to the cloud server 20 corresponding to the URL by entering the cloud account name and cloud password (step S129), and retrieves the program list from the management information of the cloud server 20 (step S130). This program list may also be called the cloud recording program list or program list. The master unit 10, for example, in response to an input operation by the user, determines the content of the program to be dubbed from the program list and accepts the start of the dubbing to the optical disc (step S131).

[0152] Subsequently, the master unit 10 reads the management information of the program to be dubbed from the cloud server 20 (step S132) and writes the management information of that program to the optical disc located in the master unit 10 (step S133). Then, the master unit 10 reads the stream data of the program to be dubbed from the cloud server 20 (step S134). The master unit 10 decrypts the read stream data using the content key, further encrypts it for the optical disc, and records the encrypted stream data to the optical disc (step S135). The master unit 10 updates the number of dubs (also called the DUB count) of that program by, for example, decrementing it (step S136). Here, if the DUB count becomes 0 as a result of the update, the master unit 10 deletes the content key of that program and deletes the program from the cloud service (i.e., the cloud server 20) (step S137). Then, the master unit 10 logs out from the cloud server 20 (step S138).

[0153] Figure 19 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when a slave unit 30 deletes its registration.

[0154] First, for example, the child device 30, which is a smartphone, enters its account name and password into the management server 40 to log in (step S141). Next, the child device 30 enters its child device ID into the management server 40 to request deletion of the child device (step S142).

[0155] In response to a request from the child device 30, the management server 40 searches for the child device ID of the child device 30 to be deleted in the child device list L3 and deletes the entry with that child device ID (step S143). In other words, the management server 40 deletes the child device ID and the IP address associated with that child device ID from the child device list L3. Next, the management server 40 searches for the parent / child set information with that child device ID in the account information L2 and deletes the entry that is the parent / child set information (step S144). Then, the child device 30 logs out of the management server 40 (step S145).

[0156] Figure 20 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when a slave unit 30 deletes the registration of another slave unit 30. For example, slave unit 30 is a PC, and the other slave units 30 are smartphones.

[0157] First, the PC enters its account name and password into the management server 40 to log in (step S146). Then, the PC requests the child device list L3 from the management server 40 (step S147).

[0158] The management server 40 sends the child device list L3 to the PC in response to a request from the PC (step S148). Upon receiving the child device list L3, the PC determines which child device 30 (i.e., smartphone) to be deleted from the child device list L3, for example, in response to input by the user (step S149). The PC then inputs the child device ID of the determined smartphone to the management server 40 and requests the deletion of the child device (step S150).

[0159] In response to a request from the PC, the management server 40 searches for the child device ID of the smartphone to be deleted in the child device list L3 and deletes the entry with that child device ID (step S151). In other words, the management server 40 deletes the child device ID and the IP address associated with that child device ID from the child device list L3. Next, the management server 40 searches for the parent / child device set information with that child device ID in the account information L2 and deletes the entry that is the parent / child device set information (step S152). Then, the PC logs out of the management server 40 (step S153).

[0160] Figure 21 is a sequence diagram showing an example of a first processing operation included in the processing operation of the recording and playback system 100 when the slave unit 30 changes cloud services.

[0161] First, for example, the client device 30, which is a PC, enters its account name and password into the management server 40 to log in (step S161) and requests the management server 40 to perform cloud service registration processing (step S162). In response to the request from the client device 30, the management server 40 requests the client device 30 to input the information necessary for cloud service registration processing (step S163).

[0162] The slave unit 30 accepts inputs such as the cloud account name, cloud password, email address, and payment information in response to user input operations, as inputs necessary for the cloud service registration process (step S164). The slave unit 30 then transmits this information to the management server 40 (step S165).

[0163] When the management server 40 receives the above information from the slave device 30, it sends that information to the cloud server 20 and requests the cloud server 20 to create a cloud account (step S166). The cloud server 20 checks the information (i.e., the input information) and creates a cloud account according to the content of that information (step S167). Then, the cloud server 20 notifies the management server 40 that the cloud account creation is complete and provides the access URL (step S168). When the management server 40 receives the notification from the cloud server 20, it notifies the slave device 30 that the cloud account creation is complete (step S169).

[0164] When the child device 30 receives notification that the cloud account creation is complete, it obtains the cloud service list L4 from the management server 40 (step S170) and identifies the cloud services currently available to the child device 30 from that cloud service list L4 (step S171). Note that the cloud password and parent device password may be omitted from the cloud service list L4 provided to the child device 30 (if they are managed in the management list of the parent device 10). Next, the child device 30 obtains the IP address associated with the parent device ID of the identified cloud service (i.e., the parent device IP address) from the management server 40 (step S172).

[0165] Figure 22 is a sequence diagram showing an example of the second processing operation in the recording and playback system 100 when the slave unit 30 changes cloud services. Note that the second processing operation is an operation that continues from the first processing operation.

[0166] The child unit 30 attempts to log in to the parent unit 10 using the parent unit's IP address obtained in step S172 of Figure 21 and the parent unit password for the parent unit 10 corresponding to that IP address (step S175). The child unit 30 then determines whether the login was successful or not based on the process in step S175 (step S179). If the child unit 30 determines that the login was unsuccessful (No in step S179), it terminates the process for changing the cloud service of the child unit 30. On the other hand, if the child unit 30 determines that the login was successful (Yes in step S179), it requests the management server 40 to delete the parent unit ID and parent unit password of the parent unit 10 from the entry of the original cloud service (step S180). The original cloud service is the cloud service identified in step S171 of Figure 21. In other words, the request is to delete the parent unit ID and parent unit password associated with the cloud service ID of the original cloud service in the cloud service list L4.

[0167] The management server 40, in response to a request from the child device 30, deletes the parent device ID and parent device password from the original cloud service entry (step S181).

[0168] Next, the child unit 30 requests the management server 40 to set the parent unit ID and parent unit password for the new cloud service entry (step S182). In response to the request from the child unit 30, the management server 40 sets the parent unit ID and parent unit password for the new cloud service entry (step S183). The new cloud service is the cloud service corresponding to the cloud account created in step S167 of Figure 21. In other words, the parent unit ID and parent unit password are associated with the cloud service ID that indicates the new cloud service in the cloud service list L4.

[0169] Then, the slave unit 30 requests the master unit 10 to delete the management information checksum, dubbing count, and content key Kc associated with the original cloud service (step S184). Furthermore, the slave unit 30 notifies the master unit 10 of the cloud service ID of the new cloud service (step S185) and logs out from the master unit 10 (step S186).

[0170] In steps S184 and S185, the slave unit 30 requests processing from the master unit 10, but the management server 40 may also make the request to the master unit 10. Also, in the example in Figure 22, the process for deleting content on the cloud server 20 is not described. This is because the content becomes unplayable data. However, since the content will remain as useless data, the slave unit 30 or the management server 40 may request the cloud server 20 to delete or format the recorded program at the time step S184 is executed.

[0171] Figure 23 is a sequence diagram showing an example of the first processing operation in the recording and playback system 100 when the master control is transferred.

[0172] First, for example, the child device 30, which is a smartphone, enters its account name and password into the management server 40 to log in (step S191) and requests the cloud service list L4 from the management server 40 (step S192). In response to the request from the child device 30, the management server 40 sends the cloud service list L4 to the child device 30 (step S193). Note that the cloud password and master device password may be omitted from the cloud service list L4 provided to the child device 30.

[0173] When the child unit 30 receives the cloud service list L4, it determines from the cloud service list L4 which cloud service (hereinafter also called the cloud service to be processed) is subject to the transfer of master unit rights, for example, in response to input from the user (step S194). In the transfer of master unit rights, the master unit 10 associated with the cloud service to be processed is changed. Next, the child unit 30 requests the management server 40 to rediscover the master unit from the home network (step S195). In response to the request from the child unit 30, the management server 40 sends the master unit list L5 to the child unit 30 (step S196). Note that the master unit password is omitted from the master unit list L5.

[0174] When the child unit 30 receives the parent unit list L5, it selects from the parent unit list L5 the parent unit 10 associated with the cloud service to be processed (hereinafter also called the parent unit 10 from the source) and the parent unit to be newly associated with the cloud service to be processed (hereinafter also called the parent unit 10 to the destination) and specifies them to the management server 40. In other words, the child unit 30 inputs the cloud service ID of the cloud service to be processed, the parent unit ID and password of the parent unit 10 from the source, and the parent unit ID and password of the parent unit 10 to the destination, to the management server 40 and requests a change to the parent unit 10 (step S197).

[0175] In response to a request from the child unit 30, the management server 40 determines whether the parent unit ID and parent unit password of the parent unit 10 from which the migration originated match the parent unit ID and parent unit password in the entry for the cloud service to be processed (step S198). The parent unit ID and parent unit password in the entry for the cloud service to be processed are the parent unit ID and parent unit password associated with the cloud service ID of the cloud service to be processed in the cloud service list L4. If the management server 40 determines that they do not match (No in step S199), it terminates the process for migrating the parent unit rights. If it determines that they match (Yes in step S199), it logs in to the first parent unit (step S200). The first parent unit is the parent unit 10 from which the migration originated, as described above.

[0176] Furthermore, the second master unit 10 at the destination of the relocation, as described above, configures the home network settings and sets the master unit password in response to user input (step S201). In other words, the second master unit is connected to the home network and holds the master unit ID, IP address, and master unit password.

[0177] Figure 24 is a sequence diagram showing an example of the second processing operation in the recording and playback system 100 when master control is transferred. Note that the second processing operation is an operation that continues from the first processing operation.

[0178] The management server 40 attempts to log in to the second master unit, which is the master unit 10 to which the transfer is made, using the master unit ID and master unit password of the second master unit (step S211). The management server 40 determines whether the login was successful or not based on the process in step S211 (step S213). If the management server 40 determines that the login was unsuccessful (No in step S213), it terminates the process for transferring master unit rights. On the other hand, if the management server 40 determines that the login was successful (Yes in step S213), it requests information such as the management information checksum, content key set, and number of dubbings from the first master unit and obtains that information from the first master unit (step S214). The content key set consists of one or more content keys Kc. Furthermore, the management server 40 requests the second master unit to write the obtained information, such as the management information checksum, content key set, and number of dubbings, and writes that information to the second master unit (step S215).

[0179] Next, the management server 40 updates the master unit ID in the cloud service entry of the cloud service list L4 (step S216). In other words, the management server 40 changes the master unit ID associated with the cloud service ID of the cloud service to be processed in the cloud service list L4 from the master unit ID of the first master unit to the master unit ID of the second master unit. Furthermore, the management server 40 requests the first master unit to delete information such as the management information checksum, content key set, and number of copies held by the first master unit (step S217). Then, the management server 40 logs out from the first master unit (step S218), logs out from the second master unit (step S219), and notifies the child unit 30 that the migration work is complete (step S220). When the child unit 30 receives notification that the migration work is complete, it logs out from the management server 40 (step S221).

[0180] Figure 25 is a sequence diagram showing an example of the processing operation in the recording and playback system 100 when the master unit 10 is transferred.

[0181] First, the child device 30, for example, a smartphone, enters its account name and password into the management server 40 to log in (step S231). Next, the child device 30 enters the parent ID and parent password of the parent device 10 to be transferred into the management server 40 and requests the management server 40 to delete the parent device 10 (step S232).

[0182] In response to a request from the child unit 30, the management server 40 searches for the parent unit ID in the parent unit list L5 and identifies the parent unit password associated with that parent unit ID (step S233). The management server 40 then determines whether the identified parent unit password matches the parent unit password entered in step S232 (step S234). If the management server 40 determines that the parent unit passwords do not match (No in step S234), it terminates the process for transferring the parent unit 10. On the other hand, if the management server 40 determines that the parent unit passwords do match (Yes in step S234), it deletes the entry for the parent unit ID entered in step S232 from the parent unit list L5. Furthermore, the management server 40 clears the parent unit ID from the cloud service list L4 and deletes the entry for that parent unit ID (i.e., the parent / child unit set information) from the parent / child unit association list in account information L2 (step S235).

[0183] Furthermore, the transferred master unit 10 resets the personal information it holds in response to, for example, an input operation by the user (step S236).

[0184] (Summary of the embodiments) As described above, the slave unit 30 in this embodiment is a terminal device used in the recording and playback system 100. In other words, the recording and playback system 100 includes a cloud server device which is the cloud server 20, a recording device which is the master unit 10, and a terminal device which is the slave unit 30. The recording device receives and encrypts the distributed content, and records the encrypted content to the cloud server device via the internet. The terminal device plays back that content. Such a terminal device comprises a circuit and a memory connected to the circuit. The circuit uses the memory to perform device authentication with the recording device, obtains an encrypted content key from the recording device, decrypts the content key using a shared key shared between the recording device and the terminal device, accesses the cloud server device without going through the recording device, reads the content recorded and encrypted on the cloud server device, decrypts the read content using the content key, and plays it back.

[0185] For example, in conventional remote viewing, both the master unit and the slave unit support content protection technologies such as DTCP. Furthermore, device authentication is performed between the master unit and the slave unit, guaranteeing viewing within the scope of private use. This is due to the constraints imposed by a system configuration in which the master unit holds the content and that content can only be played back via the master unit. However, in the case of recording content to a cloud server device (i.e., cloud recording), the destination of the recorded content may be a general-purpose cloud server device. Such general-purpose cloud server devices may not support DTCP, and access to content on the cloud server device is possible from any PC if the URL of the content or the cloud server device is known. Moreover, that PC does not need to access the content via the master unit. In such a situation, the technologies described in the aforementioned Patent Documents 1 and 2 make it difficult to adequately protect content, guarantee the scope of private use, and provide users with free playback functionality.

[0186] However, in this embodiment, the terminal device, which is the slave device 30, performs device authentication with the recording device, which is the master device, obtains an encrypted content key Kc from the recording device, and uses the content key Kc to decrypt and play back the content read from the cloud server device. Therefore, when the terminal device plays back content directly from the cloud server device, it can adequately protect the content, guarantee the scope of private use, and provide the user with a free playback function. In other words, appropriate slave device access control can be achieved.

[0187] Furthermore, in the terminal device (i.e., the slave unit 30) in this embodiment, the circuit obtains the shared key Kp transmitted from the management server 40 to the slave unit 30 and the master unit 10 by performing device authentication with the master unit 10 via the management server 40. As a result, the shared key Kp is shared between the slave unit 30 and the master unit 10 through device authentication, thereby increasing the strength of security.

[0188] Furthermore, the recording management system in this embodiment is a system used in the recording and playback system 100. That is, the recording and playback system 100 includes a cloud server device which is a cloud server 20, a recording management system, and a terminal device which is a slave device 30. The recording management system receives and encrypts the distributed content and records the encrypted content to the cloud server device via the internet. The terminal device plays back the content. Specifically, the recording management system includes a circuit and at least one memory, the at least one memory which holds validity determination information and a content key associated with the cloud server device. The circuit reads the content key from at least one memory and uses it to encrypt the content as described above, reads the validity determination information from at least one memory and uses the validity determination information to determine the validity of the content recorded on the cloud server device. The recording management system may also include a recording device which is a master device 10 and a management server device which is a management server 40. That is, the recording management system includes a recording device that records content to the cloud server device and a management server device which is connected to the recording device via the internet. In this case, each of the aforementioned circuits and at least one memory is provided in the recording device or management server device. The validity determination information is information indicating at least one of the following: a checksum for the content management information, a hash value, and the number of times the content has been dubbed.

[0189] As described in the aforementioned Patent Documents 1 and 2, digital data is much easier to copy and tamper with than analog data. Furthermore, when a cloud server is used as the recording destination for digital content, it is possible to access the cloud server from any device such as a PC, making unauthorized use, such as copying the content, more likely. In conventional recording of content with a recorder, the content and information related to the protection of the content (content key, number of copies, etc.) are recorded together in the HDD (Hard Disk Drive). In such methods, a proprietary file system is used, or device binding information is stored in an area inaccessible to the user. For example, in SQV (SeeQVault®) and BD discs (Blu-ray® Disc), information is stored in an area requiring secure access to prevent unauthorized copying. However, when content is recorded on a cloud server, it is possible to access the content from any PC and manipulate the files, so if the content is a file, it is possible to easily create a copy of that content. Furthermore, if the cloud server device is a general-purpose cloud server device, it is impractical to make that cloud server device compatible with secure access and other features.

[0190] Therefore, in the recording management system of this embodiment, information related to content protection is managed in at least one memory location, which is inaccessible to unspecified users, rather than on the cloud server device, and is linked to the cloud server device. The information related to content protection is validity determination information or content keys. As a result, the recording management system, i.e., the master unit 10 or management server 40, manages the validity determination information (checksum of management information, hash value, number of dubbings per program, etc.) and content keys linked to the cloud server device. Therefore, even if a copy of the content is created illegally, it will be treated as invalid and cannot be played back. In other words, it is possible to implement appropriate measures against illegal copying on the cloud service.

[0191] Note that the validity determination information may also be a flag used to determine the validity of the content.

[0192] Furthermore, in the recording management system of this embodiment, when management information is maintained and updated in both the recording management system and the cloud server device, the circuit of the recording management system determines the validity of the content recorded on the cloud server device by comparing the validity determination information obtained from the management information of the recording management system with the validity determination information obtained from the management information of the cloud server device. As a result, the validity determination information of the recording management system and the validity determination information of the cloud server device are compared, and if, for example, they are different from each other, the content is determined to be invalid. As a result, the validity of the content can be appropriately determined.

[0193] Furthermore, the management server 40 in this embodiment is a management server device used in the recording and playback system 100. In other words, the recording and playback system 100 comprises a cloud server device which is a cloud server 20, a first recording device which is a master unit 10, a terminal device which is a slave unit 30, and a management server device which is a management server 40. The first recording device receives and encrypts the distributed content and records the encrypted content to the cloud server device via the internet. The terminal device plays back the content. The management server device is connected to the first recording device via the internet. Such a management server device comprises a circuit and a memory connected to the circuit. The memory holds first identification information for identifying the first recording device in association with the cloud server device. When the first recording device is replaced with a second recording device, the circuit replaces the first identification information held in the memory in association with the cloud server device with second identification information for identifying the second recording device, and transfers the protection information held in the first recording device, which is used to protect the content, to the second recording device. This protection information includes, for example, the content key, the checksum or hash value of the management information, and the number of copies made.

[0194] Even with conventional methods, functions exist for transferring and dubbing recorded programs between recorders. However, such transfers of recorded programs require moving the recorded programs themselves, as they reside on the recorder's internal HDD or a device-bound USB (Universal Serial Bus) HDD. Applying this conventional method to cloud recording, where content is recorded to a cloud server 20, would involve the cumbersome process of first reading the recorded program data from the cloud server 20, decrypting it, encrypting it for DTCP transmission and reception, and then decrypting it again at the destination, encrypting it locally, and recording it to the internal HDD or other device. In other words, the target of the transfer is the recorded program itself, and since that recorded program is stored on the recorder, the recorded program itself must be moved. This is therefore a very cumbersome process.

[0195] However, considering that in cloud recording the data (i.e., recorded programs) resides on the cloud server 20, it is not necessarily required to move the recorded programs themselves. It is sufficient if the cloud server 20 can move the access rights to the recorded programs and the information indicating the validity of the data (i.e., protection information).

[0196] Therefore, in this embodiment, when the first recording device is replaced with the second recording device, the management server device replaces the first identification information of the first recording device associated with the cloud server device with the second identification information of the second recording device. In other words, the access rights to the content of the cloud server device are transferred to the second recording device. Furthermore, the management server device transfers the protection information held in the first recording device to the second recording device.

[0197] This makes it possible to easily and efficiently transfer the ownership of the main unit 10, that is, from the first recording device to the second recording device, while adequately protecting the content. Furthermore, such a transfer is considered to be within the scope of personal use and does not exceed the realm of private use. In other words, it enables the appropriate transfer of the main unit 10.

[0198] Furthermore, in this embodiment, when the first recording device is removed from the recording and playback system 100, the management server device circuit performs at least one of the following: (a) deletion of content recorded on the cloud server device by the first recording device, (b) deletion of cloud account information for accessing the cloud server device held in the first recording device or memory, and (c) deletion of first identification information held in memory in association with the cloud account information. For example, in (b), the cloud service information L11 or L12 shown in Figure 6 is deleted as cloud account information. Alternatively, in (b), the cloud service ID, URL, cloud account name, and cloud password of the cloud service list L4 shown in Figure 4 or Figure 5 are deleted as cloud account information. In (c), the master unit ID of the cloud service list L4 shown in Figure 4 is deleted as first identification information.

[0199] Even with conventional recorders, it is recommended to reset personal information and format the HDD when transferring ownership to another person. For recorders that support cloud recording, this is insufficient; in addition, it is necessary to prohibit access to recorded programs on the cloud service or delete recorded programs from the cloud service. If the user forgets to perform these steps, the actions taken by the transferred recorder may exceed the scope of private use.

[0200] Therefore, in this embodiment, as described above, content recorded on the cloud server device is deleted, and cloud account information is deleted (or reset). If the cloud account information recorded on the first recording device or the management server device is deleted (or reset), the first recording device will no longer be able to access the cloud server device. Furthermore, if the management server device manages the cloud service list L4, it is also possible to prevent access from the first recording device by logging into the management server device from a smartphone, PC, etc., and deleting the entry in the cloud service list L4. Thus, unauthorized access to the cloud server device by the transferred first recording device can be sufficiently suppressed, and the proper transfer of the first recording device, i.e., the master unit, can be easily realized.

[0201] Furthermore, "managing information" in this disclosure means retaining that information, and may also mean modifying or deleting that information.

[0202] Furthermore, the protection information in this embodiment includes information indicating at least one of the following: a content key Kc for decrypting the content, a checksum for the content management information, a hash value, and the number of times the content has been dubbed. As a result, the protection information used to effectively protect the content is transferred from the first recording device to the second recording device, thereby increasing the strength of security and enabling a proper migration of the master unit 10.

[0203] (Other forms, etc.) Although systems, devices, etc. relating to one or more embodiments of this disclosure have been described above based on embodiments, this disclosure is not limited to those embodiments. Various modifications to the above embodiments that a person skilled in the art could conceive of may also be included in this disclosure, as long as they do not deviate from the spirit of this disclosure.

[0204] The following cases are also included in this disclosure.

[0205] (1) The at least one device described above is specifically a computer system consisting of a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), a hard disk unit, a display unit, a keyboard, a mouse, etc. A computer program is stored in the RAM or hard disk unit. The at least one device described above achieves its function by the operation of the microprocessor in accordance with the computer program. Here, the computer program is composed of a combination of multiple instruction codes that indicate commands to the computer in order to achieve a predetermined function.

[0206] (2) Some or all of the components constituting at least one of the above-described devices may be made up of a single system LSI (Large Scale Integration). The system LSI is a multi-functional LSI manufactured by integrating multiple components onto a single chip, and specifically, it is a computer system comprising a microprocessor, ROM, RAM, etc. The RAM stores a computer program. The system LSI achieves its function by operating the microprocessor in accordance with the computer program.

[0207] (3) Some or all of the components constituting at least one of the above-described devices may consist of an IC card or a standalone module that is detachable from the device. The IC card or module is a computer system consisting of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-described multi-function LSI. The IC card or module achieves its function by the operation of the microprocessor in accordance with a computer program. The IC card or module may be tamper-resistant.

[0208] (4) The disclosure may also be the methods described above. Alternatively, it may be a computer program that implements these methods using a computer, or a digital signal consisting of a computer program.

[0209] Furthermore, this disclosure may also refer to a computer program or digital signal recorded on a computer-readable recording medium, such as a flexible disk, hard disk, CD (Compact Disc)-ROM, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray® Disc), semiconductor memory, etc. Alternatively, it may refer to a digital signal recorded on such a recording medium.

[0210] Furthermore, this disclosure may also include the transmission of computer programs or digital signals via telecommunications lines, wireless or wired communication lines, networks such as the Internet, data broadcasting, etc.

[0211] Alternatively, the program or digital signal may be carried out by another independent computer system by recording and transferring it on a recording medium, or by transferring the program or digital signal via a network or the like. [Industrial applicability]

[0212] This disclosure can be applied, for example, to recording and playback systems that record and play back content such as television programs. [Explanation of Symbols]

[0213] 10. Main unit (recording device) 20. Cloud Server (Cloud Server Device) 30, 31, 32, 33 Sub-unit (terminal device) 40 Management Server 41 Account Management Department 42 Shared key management section 43. Sub-unit Management Department 44 Cloud Service Account Management Department 45 Master Unit Management Department 100 Recording and Playback Systems Kp shared key Kc Content Key L1 Account List L2 Account Information L3 Sub-device list L4 Cloud Services List L5 Main Unit List L11, L12 Cloud Service Information L13 Content-related information

Claims

1. A recording management system used in a recording and playback system, The aforementioned recording and playback system is Cloud server device and A recording management system that receives and encrypts the distributed content, and records the encrypted content on the cloud server device via the internet, The system includes a terminal device that obtains an encrypted content key via the internet, decrypts the content key, and plays the content. The aforementioned recording management system is It comprises a circuit and at least one memory, The aforementioned at least one memory is The validity determination information and the content key are associated with and stored in the cloud server device. The aforementioned circuit is The content key is read from the at least one memory and used to encrypt the content. The validity determination information is read from at least one memory, and the validity of the content recorded on the cloud server device is determined using the validity determination information. Recording management system.

2. The aforementioned recording management system is A recording device that records the aforementioned content to the aforementioned cloud server device, The recording device is equipped with a management server device that is connected to the Internet via the Internet, Each of the aforementioned circuit and the at least one memory is provided in the recording device or the management server device. The recording management system according to claim 1.

3. The aforementioned effectiveness determination information is, This information indicates at least one of the following: a checksum, a hash value, and the number of times the content has been copied, for the management information of the content. The recording management system according to claim 1 or 2.

4. When the management information is maintained and updated in both the recording management system and the cloud server device, The aforementioned circuit is By comparing the effectiveness determination information obtained from the management information of the recording management system with the effectiveness determination information obtained from the management information of the cloud server device, The validity of the content recorded on the cloud server device is determined. The recording management system according to claim 3.

5. A control method performed by a recording management system used in a recording playback system, The aforementioned recording and playback system is Cloud server device and A recording management system that receives and encrypts the distributed content, and records the encrypted content on the cloud server device via the internet, The system includes a terminal device that obtains an encrypted content key via the internet, decrypts the content key, and plays the content. In the aforementioned control method, The validity determination information and the content key are associated with and stored in the cloud server device. The content key is read from memory and used to encrypt the content. The validity determination information is read from the memory, and the validity of the content recorded on the cloud server device is determined using the validity determination information. Control method.

6. A program for a recording management system used in a recording playback system, The aforementioned recording and playback system is Cloud server device and A recording management system that receives and encrypts the distributed content, and records the encrypted content on the cloud server device via the internet, The system includes a terminal device that obtains an encrypted content key via the internet, decrypts the content key, and plays the content. The aforementioned program, The validity determination information and the content key are associated with and stored in the cloud server device. The content key is read from memory and used to encrypt the content. The validity determination information is read from the memory, and the validity of the content recorded on the cloud server device is determined using the validity determination information. A program that causes the computer of the aforementioned recording management system to perform the following action.

Citation Information

Patent Citations

  • Projection of diaphragm ring of interchangeable lens

    JP1986087139A

  • Air compression type spark ignition internal combustion engine

    JP1988090618A