Content management system, content management method, and content management program
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- NOMURA RESEARCH INSTITUTE
- Filing Date
- 2024-05-16
- Publication Date
- 2026-08-03
AI Technical Summary
Existing content distribution systems face issues with unauthorized access and easy duplication of content data, leading to risks of illegal use and hindered healthy circulation of tokens.
A content management system that includes a content acquisition unit, registration unit, token issuance, and usage verification to manage and control access to content data, using blockchain technology for token distribution and encryption to ensure legitimate use.
Prevents unauthorized use of content data and ensures healthy circulation by verifying the legitimacy of access requests and encrypting content, thereby protecting content rights and promoting a digital content economy.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a content management system, a content management method, and a content management program. Regarding Ram. [Background technology]
[0002] 2. Description of the Related Art Conventionally, a system for providing content to a terminal of a legitimate right holder is known.
[0003] For example, the content distribution device described in Patent Document 1 uses an access token. When a content distribution request is received from a user terminal, the The device issues an access key to the user terminal for the purpose of authentication. The validity of various requests is judged from the access key, and the validity of the access key is confirmed. Only when the content is received, the device accepts various requests from the user terminal. Once distribution is complete, the access key will be invalidated. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2003-345762 A Summary of the Invention [Problem to be solved by the invention]
[0005] The content distribution device described in Patent Document 1 includes an access token and an access Content is provided to user terminals equipped with a key. The user device that obtained the access token and access key, and the content data are illegally User terminals that may be used, etc., and user terminals to which content data should not be provided There was a risk that content data would be provided to
[0006] In addition, since content data can be easily copied, Even if a user does not have the issued token, the user can use the content corresponding to the token. It is anticipated that content data may be used illegally, which could disrupt the sound distribution of the token. There was a risk.
[0007] Therefore, the present invention provides a content management system capable of preventing unauthorized use of content data. The present invention aims to provide a content management system, a content management method, and a content management program. Let us assume that.
[0008] The present invention also prevents unauthorized use of content data, and protects and controls content data. By controlling access to content data, we ensure the sound circulation of tokens. It is expected that this will contribute to the development of a digital content economy. [Means for solving the problem]
[0009] A content management system according to one aspect of the present invention includes a registrant who registers content data. a content acquisition unit that acquires content data based on an operation of the registrant terminal; Content registration that accepts registration of content data based on the content data Based on the registered content data, A token issuing unit that issues a token and a requester terminal that requests the provision of content data. In response to a request for providing content data based on the token acquired from the requester terminal, and a usage verification unit that verifies whether or not the content data can be used in the content server.
[0010] A content management method according to one aspect of the present invention includes: The content data is acquired based on the operation of the registered user's terminal. Based on the content data, the registration of the content data is accepted, and the registered content data is Based on the data, a token corresponding to the registered content data is issued, and the content data is The token-based content data is obtained from a requester terminal of a requester requesting the provision of the content data. In response to a request for providing the content data, the content data is verified as to whether it is available on the requester's terminal.
[0011] A content management program according to an aspect of the present invention is a program for managing content data in a computer. The content data is acquired based on the operation of the registrant's terminal. The content acquisition unit receives registration of content data based on the acquired content data. A content registration section that registers the registered content data and a content registration section that registers the registered content data. A token issuing unit issues a token corresponding to the content data, and a content server requests the provision of the content data. The token is obtained from a requester terminal of the requester, and the requester requests content data based on the token. In response, a usage verification unit verifies whether the content data can be used in the requester terminal. Make it happen.
[0012] In the present invention, the term "part" does not simply mean a physical means, but rather the " This also includes cases where the functions of a "part" or "unit" are realized by software. Even if the functions of a device are realized by two or more physical means, devices, or software, , two or more "parts" or functions of a device are performed by one physical means, device, or software. It may be realized. Effect of the Invention
[0013] According to the present invention, a content management system capable of preventing unauthorized use of content data is provided. It is possible to provide a system, a content management method, and a content management program. . [Brief description of the drawings]
[0014] [Figure 1] FIG. 1 is a diagram showing an overview of processing in a content management system 100 according to an embodiment of the present invention. [Diagram 2] 1 is a diagram showing a configuration of a content management system 100 according to an embodiment of the present invention. [Diagram 3] 10 is a diagram showing an example of content registration information stored in storage unit 105. FIG. [Figure 4] FIG. 13 is a diagram showing an example of a token issued by the token issuing unit 135. [Diagram 5] 2 is a sequence chart showing an example of processing in the content management system 100. [Figure 6] 2 is a sequence chart showing an example of processing in the content management system 100. [Figure 7] 13 is a sequence chart showing an example of processing in a modified example of the content management system 100. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0015] A preferred embodiment of the present invention will be described with reference to the accompanying drawings. FIG. 1 is a diagram showing an overview of processing in a content management system 100 according to an embodiment.
[0016] The content management system 100 is an information management system implemented by a content management program. The content data is processed based on the operation of the registrant's terminal. From a requester terminal of a requester who issues a corresponding token and requests the provision of content data In response to a request for providing content data based on the acquired token, Verify the availability of the content data.
[0017] Here, the content data includes, for example, images, videos, music, software, and model data. Even if the data is related to digital works such as data, access tokens (virtual keys), good.
[0018] The image may be, for example, a photograph or an illustration. The image may be an electronically generated image. It may also be a developed photograph or a hand-drawn or printed illustration. The image may be an image digitized by a predetermined method (for example, scanning).
[0019] Examples of moving images include video images, animation images, and computer graphics images. may be also possible.
[0020] The music may be, for example, audio data including songs, conversations, sounds, etc. The software may be, for example, an application for content creation or other purposes. The model data may be, for example, a person or a question. Learning of problem-specific model data and mathematical models, or artificial intelligence with specific personalities and tendencies It may be a finished model.
[0021] Content data includes any other data provided via subscription. may be also possible.
[0022] First, the content management system 100 performs the following operations based on the operation of the registrant of the content data: For example, content data is acquired from a registrant terminal and registered (S101). The content management system 100 stores content data in an external storage system. The content management system 100 may store the registered content data (S101a). A token corresponding to the data is issued (S102) and circulated on the blockchain system. (S103).
[0023] Next, the content management system 100 receives a request from a requester requesting the provision of content data. A request for providing content data based on the token is obtained from the requester terminal (S104 The content management system 100 checks whether the requester can use the content data. The content data is provided to the requester (S105). The content data may be provided via a storage system (S105a).
[0024] FIG. 2 is a diagram showing a configuration of a content management system 100 according to an embodiment of the present invention. The content management system 100 includes a registrant terminal 200, a requester terminal 300, a storage Blockchain system 400 and blockchain system 500 and networks such as the Internet The content management system 100 is communicatively connected to the content management system 100 via a network. This will be explained later.
[0025] The registrant terminal 200 is a computer used by the registrant, and may be a smartphone, tablet, or the like. The registrant can use the registrant terminal 200 to enter information about the registrant's computer. Content data is provided to the content management system 100 and registered.
[0026] The registrant is, for example, a person who has a legitimate right to register content data. For example, the person in question may be the author of the content data, or may be the person in question who owns the copyright to the content data. The copyright holder may be a person who owns the copyright (e.g. copyright).
[0027] The registrant registers content data in the content management system 100 and creates a corresponding token. By issuing a kun, you grant the right to use the content data (e.g., viewing or The registrant can use the content data, for example, You can sell the rights to it to someone else.
[0028] The requester terminal 300 is a computer used by the requester, and may be a smartphone, tablet, etc. These include mobile terminals and personal computers.
[0029] The requester obtains a token corresponding to the content data registered by the registrant (e.g. The requester then acquires the right to use the content data by purchasing the content data. Based on the token, the right to use the content data is exercised. Specifically, The requester transmits the content to the content management system 100 via the requester terminal 300. The content data providing unit 101 makes a request for providing the content data based on the token corresponding to the content data.
[0030] The storage system 400 stores the content registered in the content management system 100. The storage system 400 is an external information processing system that stores data. , capable of communicating with the requester terminal 300 and providing content data to the requester terminal 300. It is possible.
[0031] The storage system 400 may be implemented, for example, as a distributed file system (e.g., IPFS ( It may also be the InterPlanetary File System).
[0032] A user (e.g., a requester) can freely access the storage system 400 through a terminal, for example. and can freely obtain data stored in the storage system 400. can.
[0033] The blockchain system 500 is issued in response to the registered content data. It is a system that uses blockchain technology to manage the tokens that are created. The transaction system 500 may, for example, determine whether a token is legitimate in response to a transaction such as buying or selling of the token. It manages information about the rights holders (e.g. owners) and records it in a distributed ledger. The chain system 500 is, for example, an NFT (Non-Fungible Token) marketplace ( For example, an NFT marketplace implemented with smart contracts. .
[0034] In FIG. 2, the registrant terminal 200, the requester terminal 300, the storage system 40 0 and blockchain system 500 are shown one by one, but each has multiple A number of registrant terminals 200, a requester terminal 300, a storage system 400, a blockchain The present invention may also be applied to an application system 500.
[0035] Next, the content management system 100 will be described in detail. The system 100 includes a storage unit 105, a content acquisition unit 110, a processing unit 115, and a content Registration unit 120, encryption unit 125, encrypted content providing unit 130, token issuing unit 135 , provision request acquisition unit 140, usage verification unit 145, content provision unit 150, key provision unit 155 Each unit shown in FIG. 2 uses a storage area, processes a program stored in the storage area, and This can be realized by a processor executing a program.
[0036] The storage unit 105 stores information to be processed in the content management system 100 . The storage unit 105 can store, for example, content registration information, which will be described later.
[0037] The content acquisition unit 110 acquires content data based on the operation of the registrant terminal 200. Get it.
[0038] The content acquisition unit 110 acquires content data from, for example, the registrant terminal 200. In addition, the content acquisition unit 110 may, for example, In addition, content data may be acquired from an external information processing system.
[0039] In addition, the content acquisition unit 110 may store a predetermined number of characters indicating that the content is registered based on the operation of the registrant. In this case, the registrant may obtain the content data that has been subjected to the above processing. The registrant terminal 200 performs the predetermined processing on the content data, The content data that has been subjected to a predetermined processing is provided to the content management system 100. do.
[0040] At this time, the registrant uses the private key of the registrant provided in the registrant terminal 200 to This allows the registrant to legitimately carry out the specified processing. The content management system 1 is a place where users can easily share their content data with others. You can prove that you are registered with 00.
[0041] In this case, the registrant enters the content data for the content management system 100. In addition to providing the public key corresponding to the private key used in the specified processing, The content management system 100 may then provide the content to the content management system 100. It is verified whether the predetermined processing performed at the registrant terminal 200 has been performed legitimately. It is possible.
[0042] The predetermined processing to indicate that registration is based on the operation of the registrant is described later. The processing may be the same as that in the processing unit 115.
[0043] The processing unit 115 performs registration on the content data acquired by the content acquisition unit 110. The registration is made based on the operation of the registrant. Hereinafter, the predetermined processing indicating that the registration is based on the above will be simply referred to as the predetermined processing. .
[0044] The predetermined processing may be, for example, adding predetermined information to the content data. stomach.
[0045] The addition of predetermined information to content data can be, for example, It is a method of adding a digital watermark to data or a transparent image (watermark). It is also acceptable to add non-transparent images (stamps, marks, etc.) The image to be added may be a symbol indicating the registrant (for example, the registrant's signature, etc.). It may be a character string indicating the date and time of registration or the name of the registrant, or A symbol or character string (i.e., For example, it may be information that does not indicate the registrant itself.
[0046] Furthermore, the image added to the content data may be of any size. The image may be added to any position in the content data. It may be added in a small way to the corner of the content data, or in a large way to the center of the content data. good.
[0047] The predetermined processing is, for example, when the content data is processed in the content management system 100. This is sufficient as long as it indicates that the content has been registered in the content management system 100. This makes it possible to avoid duplicate registration of content data.
[0048] In addition, the predetermined processing may be performed, for example, when the content data is registered by a specific registrant. This may indicate that the administrator of the content management system 100 Or the user can know who registered the registered content data. It is possible.
[0049] The predetermined processing may be, for example, when the content data is registered. It may also be possible to show that the product has been registered by a person who has a valid right to use the product. This allows the administrator or user of the content management system 100 to access the registered content data. This allows users to know whether the data is legitimately registered.
[0050] The processing unit 115 processes, for example, a secret managed in the content management system 100. Based on the key, the content data can be subjected to a predetermined processing. The administrator or user of the content management system 100 It is possible to verify whether the specified processing performed in step 0 was legitimate. .
[0051] The processing unit 115 is managed in the content management system 100, for example. The content is encrypted based on a private key associated with each registrant. This allows the content management system to perform a specified processing on the data. The administrator or user of the system 100 can confirm who registered the registered content data. You can understand what is what.
[0052] The processing unit 115 processes the private key managed in the content management system 100. (For example, a private key corresponding to each registrant) is used to perform a predetermined operation on the content data. When the above processing is performed, the corresponding public key (for example, the public key corresponding to each registrant) Based on the above, the administrator or user of the content management system 100 (for example, (a person considering acquiring a token corresponding to content data) It is possible to verify whether the change has been made.
[0053] The content registration unit 120 registers the content based on the content data acquired by the content acquisition unit 110. Based on this, the registration of content data is accepted, and content related to the content data to be registered is provided. The content registration information is stored in the storage unit 105.
[0054] The content registration unit 120 also registers the content data that has been accepted for registration with external information. It may be stored in a memory unit of the processing system.
[0055] The content registration unit 120 registers the content acquired by the content acquisition unit 110 after a predetermined processing process. The registration of the content data may be accepted, and the content data may be processed as required. The content registration unit 120 may also accept registration of content data that is not registered. The processing unit 115 accepts registration of content data that has been subjected to a predetermined processing process. This is also fine.
[0056] The content registration unit 120 receives the content that has been subjected to a predetermined processing by the processing unit 115. When accepting the registration of content data, the content registration unit 120 performs a predetermined processing. The content data that has not been processed (i.e., the original data) and the data that has not been processed The storage unit 105 may store both the content data and the downloaded content data.
[0057] At this time, the content registration unit 120 registers the content that has not been subjected to the predetermined processing. The content data (i.e., the original data) is stored in the storage unit 105, and the encrypted data is stored in the storage unit 105. The processed content providing unit 130 receives the processed content data. The content data encrypted by the encryption unit 125 described later is sent to the storage system 40. 0. In this way, the content management system 100 can determine whether a predetermined processing has been performed. The acquired content data can be used to induce the acquisition of tokens, and The unprocessed content data (i.e., the original data) is sent to the requester terminal. 300 can be provided.
[0058] FIG. 3 is a diagram showing an example of content registration information stored in the storage unit 105. The content registration information stored in the 05 includes, for example, a content ID and content information. Includes information.
[0059] The content ID is information for identifying the content data. This is information that indicates the content of the content data, for example, the data entity of the content data. do.
[0060] In response to the registration of content data by the content registration unit 120, the encryption unit 125 The content data is encrypted to generate encrypted content data.
[0061] The encryption unit 125 encrypts key information (for example, a public key or Generate and share a key between the seeker terminal 300 and the seeker terminal 300 through an arbitrary process, for example, Diffie-Hellman key exchange. The content is confidentially managed by the content management system 100, and the requester terminal 300 ( For example, a Trusted Execution Environment (TEE) of the requester terminal 300 described later. The content data may be encrypted using a common key stored in the The encrypted content data is sent to an external information processing device by the encrypted content providing unit 130 described later. Even if the key information is provided to the system, users of terminals that do not have the corresponding key information will be unable to access the content. This will prevent unauthorized use of content data. It is possible.
[0062] The encryption process by the encryption unit 125 makes it impossible to use the content data at all, for example. Alternatively, the use of the content data may be restricted. .
[0063] The encryption process for restricting the use of content data uses key information to encrypt the content. Mosaic of content data, low resolution of content data, color, brightness, etc. of content data Change distortion, trim or cut content data, and edit content data It may be a process for generating a thumbnail image or a video image. A user (e.g., a requester) who does not have the Data, and content generated by the trimming and editing process or digest generation process You can use only a part of the content data, but you cannot use the entire content data. I can't.
[0064] The encrypted content providing unit 130 transmits the encrypted content data to the requester terminal 300 and At least one of the external information processing systems (e.g., the storage system 400) provide.
[0065] The encrypted content providing unit 130 provides encrypted content data that is completely unusable. In this way, the contents of the content data can be kept secret. It is also necessary to inform the person who wishes to acquire the token that the content data exists. This can effectively induce token acquisition.
[0066] The encrypted content providing unit 130 also provides encrypted content data with limited usage. Content data may be provided to those who wish to acquire tokens. The existence of a content data entity can be notified to the registrant or token holder. To the extent that it does not infringe the rights of the copyright holder, a part of the content data may be checked as a trial version. This can effectively induce the acquisition of tokens.
[0067] In addition to providing the encrypted content data, the encrypted content providing unit 130 Meta information (e.g., Even if you provide information about the registrant of the content data and an overview of the content data, This will allow those who wish to acquire tokens to have the right of registration or token holders protected. This allows the user to see a part of the content data without being distracted, and allows for effective conversation. Here, the information regarding the outline of the content data can be An example of such a data is thumbnail data (for example, a reduced image or a part of an image, If it is an image, a preview may be used.
[0068] The token issuing unit 135 issues a token to the registered content based on the registered content data. A token corresponding to the data is issued.
[0069] The token issued by the token issuing unit 135 may be, for example, an NFT.
[0070] The token issuing unit 135 submits the issued token to the blockchain system 500. By deploying it, the issued tokens can be circulated.
[0071] The token issued by the token issuing unit 135 is, for example, a token related to the use of content data. Here, the right to use content data is, for example, For example, a person who owns a right to dispose of content data (e.g., sell it) or a token The right to use (e.g., view or listen to) content data while in possession of the content data; Or, it may be a right to use content data for a certain period of time.
[0072] Here, the owner (or right holder) of the token, for example, 0 (e.g., a distributed ledger managed in a blockchain system 500) A person who is associated with and recorded as the owner (or rights holder) of the token in The token owner (or right holder) is not limited to natural persons or corporations, but may be any person or entity that has a specific The system may be a blockchain system (e.g., a blockchain system 500). The owner of Kun may be interpreted as the entity represented by the token's owning entity, as appropriate.
[0073] The token issued by the token issuing unit 135 may be, for example, a token conforming to a predetermined standard (e.g., E Tokens that comply with RC (Ethereum Request for Comments) 721 or ERC 1155 It may be .
[0074] In addition, the token issuing unit 135 deploys the token to the blockchain system 500. When downloading the content data, meta information about the content data (e.g. Information about the registrant and an overview of the content data may be provided. Those who are considering acquiring tokens should obtain the content data in advance when acquiring tokens. You can check part of the contents.
[0075] FIG. 4 is a diagram showing an example of a token issued by the token issuing unit 135. For example, token ID, ownership entity information, content ID, link address information, token content information, where the token further includes an issuer that identifies the issuer of the token. The token may include a user ID or issuer name information indicating the name of the issuer of the token.
[0076] The token ID is information for identifying a token issued by the token issuing unit 135.
[0077] The owning entity information is the owning entity of the token (e.g., a natural person, a legal entity, a specified The initial value of the owned entity information is, for example, The token may be information indicating the administrator of the token management system 100. The information may indicate the registrant of the content data or the blockchain system 500. .
[0078] The link address information is a storage address where the content data corresponding to the token is stored. The storage destination indicated by the link address information is, for example, a content management system. The storage unit 105 of the system 100 may be an external information processing system (e.g., The storage unit may be a storage unit of the storage system 400.
[0079] The token content information is the content of the rights regarding the use of the content data corresponding to the token. The token content information is, for example, information indicating the content while the token is in possession. It includes the word "ownership" to indicate that the data is owned.
[0080] The provision request acquisition unit 140 receives content data based on the token from the requester terminal 300. Get the provision request.
[0081] The requester performs a transaction in the blockchain system 500 through the requester terminal 300. The token issuing unit 135 acquires (e.g., purchases) a token issued by the token issuing unit 135. A predetermined transaction process is executed on the blockchain system 500, and the token The owner of the token is updated to the requester. After updating, the requester becomes the owner of the token. Then, the requester uses the requester terminal 300 to purchase the token based on the acquired token. A request is made to provide content data corresponding to the user.
[0082] The provision request acquired by the provision request acquisition unit 140 is a request for providing content data corresponding to a token. This is a request based on the right of use. For example, The right to use the content data is given to the user while he / she owns the token. If the right is to be able to view or listen to the content, the request for provision may be, for example, A request for the provision (e.g., distribution) of content data in a format in which the content data can be used. It's fine.
[0083] In response to a provision request acquired from the requester terminal 300, the usage verification unit 145 The availability of the content data in 300 is verified.
[0084] Specifically, the usage verification unit 145 verifies, for example, whether the requester terminal 300 is performing a predetermined transaction. Whether the terminal is the rightful owner of the content data associated with the token by the application process A function for verifying whether the requester terminal 300 is using the content data (right verification function), It has a function to verify whether or not a specified function for restricting the use of a certain device is provided (restriction verification function).
[0085] First, the right verification function of the usage verification unit 145 will be described. For example, information about the token recorded in the blockchain system 500 The owner of the token associated with the token requests the requester terminal 3. 00. As a result, the content management system 100 Content data can be provided to a legitimate right holder based on the token.
[0086] The owner of the token associated with the token is the requester of the requester terminal 300. When verifying whether or not the token is used, the usage verification unit 145, for example, In this case, the usage verification unit may verify whether the public key of the requester belongs to the requester. 145 may, for example, use the requester's public key to verify that the signature is made using the requester's private key. It may be possible to verify whether the file was generated using the
[0087] At this time, the authentication method of the signature by the usage verification unit 145 is not particularly limited, but for example, The authentication method may be one using Schnorr signatures (Schnorr protocol).
[0088] The content management system 100 is a blockchain system 500. The transaction of the token may or may not be monitored.
[0089] The content management system 100 manages tokens in the blockchain system 500. When a transaction is being monitored, content management system 100 Depending on the transaction, information about the transaction (e.g. new ownership of tokens) The usage verification unit 145 may then obtain information about the user and store it in the storage unit 105. is based on the information about the token transaction stored in the storage unit 105. The owner of the token associated with the token is the requester of the requester terminal 300. It may be possible to verify whether or not there is one.
[0090] The content management system 100 manages tokens in the blockchain system 500. If a transaction is not monitored, content management system 100 may, for example, In response to a provision request obtained from a requester, the blockchain system 500 is accessed, Please refer to the information regarding transactions in the blockchain system 500. Then, the usage verification unit 145 performs the following based on the information about the token transaction. The owner of the token associated with the token is the requester of the requester terminal 300. It may be possible to verify whether or not there is one.
[0091] Next, the restriction verification function of the usage verification unit 145 will be described. For example, whether the requester terminal 300 is equipped with a DRM (Digital Rights Management) environment Verify whether:
[0092] Here, DRM is a method of protecting the copyright of content data held by the legitimate owner of the content data. In order to prevent the unjust infringement of rights such as copyright, etc., we will restrict the use and duplication of content data. DRM is a mechanism that, for example, prohibits copying of content data or limits the number of times it can be copied. prohibit the use of content data on devices other than those specified, DRM protects content data by restricting the period during which the data can be used. The environment can be realized by hardware or software. There are various forms, such as those realized by a combination of hardware and software. do.
[0093] The requester terminal 300 equipped with a DRM environment is, for example, a content management system 100 Even if content data is provided by a third party, it is prohibited to use it outside the rights corresponding to the token (for example, You may not copy or modify the Content Data.
[0094] In addition, the requester terminal 300 has a predetermined function for restricting the use of the content data. When verifying whether or not the requester terminal 300 is a content It can be verified whether the content data is to be processed within the TEE in the requester terminal 300. do.
[0095] Here, the TEE is, for example, a device that runs an operating system (OS) of the terminal. It is an environment isolated from the environment of the terminal, and data can be processed in a confidential state. Users of the TEE, for example, cannot access the data itself that is processed within the TEE. However, you can obtain the results processed inside the TEE.
[0096] That is, when content data is processed inside the TEE, for example, The content data itself cannot be accessed, and copying of the content data is prohibited. The content cannot be transmitted to the TEE, but is the result of processing the content data within the TEE. The data can be used (for example, to play video content data, etc.). This allows users to use content data while preventing unauthorized use of the content data. It is possible.
[0097] As described above, the usage verification unit 145 has a right verification function and a restriction verification function. For example, the requester terminal 300 executes a transaction through a predetermined transaction process. The requester terminal 30 is a terminal of the right holder of the content data associated with the token. 0 has a predetermined function to restrict the use of content data, The use of the content data in 300 may be permitted.
[0098] In addition, the usage verification unit 145 checks whether the requester terminal 300 is performing a predetermined transaction process. and In the case where the requester terminal 300 has a predetermined function for restricting the use of the content data, In at least one of the cases, the use of the content data in the requester terminal 300 is permitted. This may be possible.
[0099] In this way, in the content management system 100, When a request for content data is made, the above-mentioned right verification function is used to verify the content. If the rights holder regarding the use of content data (in this case, the token owner) changes Even if the content data is not used, it is possible to prevent the content data from being provided to past right holders.
[0100] If the above-mentioned rights verification function is not used, the content data of past rights holders will be In particular, for example, content management companies may be unable to prevent the use of such data. The management system 100 provides key information for using the content data, and the requester receives the key information. When using the content data using the information, the requester will receive the corresponding token after the sale. There is a risk that the content data can be used continuously even if the user accesses the content data by using the key information. For example, the content management system 100 may provide the requester with link address information, and the requester may However, the storage location indicated by the link address information is accessed to obtain the content data (e.g. For example, downloading, the requester will continue to use the link even after the corresponding tokens are sold. There is a risk that the storage location indicated by the address information may be accessed and content data may be continuously used. There is.
[0101] Therefore, the content management system 100 performs verification using the above-mentioned right verification function. As a result, the content management system 100 can easily and easily retrieve content data from past rights holders. It is possible to prevent the provision of content data to the current rights holder and provide the content data to the current rights holder.
[0102] In addition, in the content management system 100, the content based on the issued token is When requesting the provision of content data, the above-mentioned restriction verification function is used to verify the content. It is possible to allow users to use content data while preventing unauthorized use of the data. .
[0103] The content providing unit 150 provides the content data according to the verification result of the usage verification unit 145. is provided to the requester terminal 300.
[0104] Specifically, the content providing unit 150, in the usage verification unit 145, The terminal 300 acquires the content associated with the token through a predetermined transaction process. The requester terminal 300 is a terminal of the rightful owner of the content data, and the requester terminal 300 controls the use of the content data. When the content data is provided to the requester terminal 300, the content data is provided to the requester terminal 300. It is possible.
[0105] In addition, the content providing unit 150 may, for example, If the terminal is a terminal of the right holder of the content data associated with the token by the authentication process, In addition, if the requester terminal 300 has a predetermined function for restricting the use of the content data, In at least one of the cases, the content data may be provided to the requester terminal 300. stomach.
[0106] The content providing unit 150 receives, for example, encrypted In this case, the content providing unit 150 can provide content data that is not available. The content data may be provided after a predetermined processing process. Unauthorized registration of the content data in the content management system 100 by the terminal 300 (Re-registration) can be avoided.
[0107] In addition, the content providing unit 150 receives content data that has not been subjected to a predetermined processing. In this way, the requester can easily receive the content data registered by the registrant. The raw data is available.
[0108] In addition, when the requester terminal 300 includes a TEE, the content providing unit 150 The TEE may then provide the content data to the requester. This prevents direct access to content data, thus preventing unauthorized use of content data. It is possible.
[0109] The content providing unit 150 also provides registered content data to an external information processing system. If the information is stored in the external information processing system, the external information processing system is The system may be instructed to provide the content data to the requester terminal 300 .
[0110] The key providing unit 155 converts the encrypted content data into The key information required for use is provided to the requester terminal 300 .
[0111] The requester terminal 300 receives the recorded data from the storage system 400. When obtaining encrypted content data stored in the Therefore, key information (for example, key information used to decrypt encrypted content data) is required. Then, the key providing unit 155 transmits the encrypted The requester terminal 300 provides the key information necessary for using the encrypted content data. The content data is used by using the key information. 0 provides the requester terminal 300 with key information used to decrypt the encrypted content data. However, the private key held by the user of the requester terminal 300 in the form of a hardware wallet, etc. may be used to decrypt the encrypted content data.
[0112] The key providing unit 155 checks in the usage verification unit 145 whether the requester terminal 300 is a The end of the right holder of the content data associated with the token through transaction processing and the requester terminal 300 has a predetermined function for restricting the use of the content data. If the key information is available, it can be provided to the requester terminal 300 .
[0113] In addition, the key providing unit 155 may, for example, Therefore, if the terminal is the terminal of the right holder of the content data associated with the token, and In a rare case where the requester terminal 300 has a predetermined function for restricting the use of content data, In at least one case, the key information may be provided to the requester terminal 300 .
[0114] In addition, if the requester terminal 300 has a TEE built therein, the key providing unit 155 The EE may provide the key material to the requester, ensuring that the requester does not have direct access to the key material. This prevents unauthorized use of content data due to leaks or reuse of key information. It is possible to do so.
[0115] In addition, when the requester terminal 300 obtains the encrypted content data from the storage system 400, If the requester terminal 300 obtains the content, the requester terminal 300 responds to the provision request to the content management system 100. The encrypted content data notified by the content management system 100 is stored. The encrypted content data may be obtained based on a predetermined link address stored in the content storage device.
[0116] In addition, the requester terminal 300 retrieves the encrypted content data from the storage system 400. When acquiring the token, the requester terminal 300 refers to the acquired token and The encrypted content data corresponding to the token recorded in the system 500 is stored. The encrypted content data may be obtained based on a predetermined link address stored in the encrypted content data.
[0117] The content data is transferred by transactions in the blockchain system 500. When the owner of the token corresponding to the encrypted content data is changed, the key information of the encrypted content data is This allows the former token owner to sell the token. Even after the authentication, the encrypted content data is encrypted based on the key information obtained from the key providing unit 155. This prevents the token from being used by anyone other than the current owner of the token. The data can be used.
[0118] The method of invalidating the key information is not limited, but for example, The 500 transaction gives you ownership of the tokens corresponding to the content data. When the user is changed, the encryption unit 125 and the encrypted content providing unit 130 The process may be performed again using different key information, resulting in the old key information becoming invalid. At this time, the content management system 100 stores the encrypted content based on the old key information. A request may be made to the storage system 400 to delete the old encrypted content data.
[0119] The content management system 100 uses the content providing unit 150 (to be described later) to When providing content data to the requester terminal 300, the content management system 100 The system includes an encryption unit 125, an encrypted content providing unit 130, and a key providing unit 155. It's okay.
[0120] FIG. 5 is a sequence chart showing an example of processing in the content management system 100. The sequence chart shown in FIG. 13 is a sequence chart showing an example of a process when data is provided to a requester terminal 300.
[0121] First, the registrant completes the content, and the registrant terminal 200 generates the content data. (S501). Note that the content is not completed by the registrant or the registrant terminal 200. The content acquisition unit 110 may acquire, for example, the registered user's information based on the operation of the registrant terminal 200. The content data is acquired from the user terminal 200 (S502).
[0122] The processing unit 115 performs a predetermined processing on the acquired content data (S5 03). Note that the content data acquired by the content acquisition unit 110 has already been subjected to a predetermined processing process. If the content data has been processed, the data is processed by the processing unit 115. does not have to be performed.
[0123] Next, the content registration unit 120 accepts the registration of the content data (S504 ).
[0124] Then, the token issuing unit 135 issues a token corresponding to the content data (S 505), and provide (deploy) it to the blockchain system 500 (S506). The requester acquires the token through the requester terminal 300 (S507). 40 receives a request for providing content data based on the token from the requester terminal 300. (S508).
[0125] In response to the provision request acquired from the requester terminal 300, the usage verification unit 145 The availability of the content data in the requester terminal 300 is verified (S509). The content providing unit 150 requests the content data according to the verification result by the usage verification unit 145. The information is provided to the user terminal 300 (S510).
[0126] The content providing unit 150 provides content data that has been subjected to a predetermined processing process. Alternatively, content data that has not been subjected to the predetermined processing may be provided. .
[0127] FIG. 6 is a sequence chart showing an example of processing in the content management system 100. The sequence chart shown in FIG. 6 is a sequence chart showing the content management system 100 FIG. 1 is a sequence diagram showing an example of a process for providing content data to the storage system 400. It is a chart.
[0128] First, the registrant completes the content, and the registrant terminal 200 generates the content data. (S601). Note that the content is not completed by the registrant or the registrant terminal 200. The content acquisition unit 110 may acquire, for example, the registered user's information based on the operation of the registrant terminal 200. The content data is acquired from the user terminal 200 (S602).
[0129] The processing unit 115 performs a predetermined processing on the acquired content data (S6 03). Note that the content data acquired by the content acquisition unit 110 has already been subjected to a predetermined processing process. If the content data is processed, the data processor 115 does not process the data. It is not necessary.
[0130] Next, the content registration unit 120 accepts the registration of the content data (S604 The encryption unit 125 encrypts the registered content data and outputs the encrypted content data. The encrypted content providing unit 130 generates the encrypted content data (S604-2). The data is provided to the storage system 400 (S604-3).
[0131] Then, the token issuing unit 135 issues a token corresponding to the content data (S 605), and provide (deploy) it to the blockchain system 500 (S606). The requester acquires the token through the requester terminal 300 (S607). 40 receives a request for providing content data based on the token from the requester terminal 300. (S608).
[0132] In response to the provision request acquired from the requester terminal 300, the usage verification unit 145 The requester terminal 300 verifies whether the content data is available (S509). The terminal acquires the encrypted content data from the storage system 400 (S609-2 The key providing unit 155 provides the requester with key information required for using the encrypted content data. The final price will be provided at the end of the month (S610).
[0133] The requester terminal 300 can store encrypted content data at any time. You can get it from System 400.
[0134] The above describes one embodiment of the present invention. The token corresponding to the content data that is registered based on the operation of the user terminal 200 is A request for providing content data based on the token issued by the requester terminal 300 In response to a request, it is possible to verify whether the content data is available at the requester terminal 300. This allows the content management system 100 to prevent unauthorized use of content data. can be avoided.
[0135] In addition, the content management system 100 detects whether the requester terminal 300 is a user of a predetermined transaction. Whether or not the terminal is a terminal of the right holder of the content data associated with the token by the processing And whether the requester terminal 300 has a predetermined function for restricting the use of the content data This allows the content management system 100 to verify whether the content It is verified whether the requester terminal 300 is one that cannot be used illegally, and the content data is This can prevent unauthorized use of data.
[0136] In addition, the content management system 100 indicates that registration is based on the operation of the registrant. The content data that has been subjected to the required processing can be acquired and registered. Therefore, the content management system 100 can collect content data registered by a legitimate registrant. Processing can be performed on the data.
[0137] In addition, the content management system 100 performs the following operations on the acquired content data: A predetermined processing process is performed to indicate that the information is registered based on the operation, and the predetermined processing process is performed. This allows the content management system to accept registration of content data that has been registered. The system 100 processes content data registered by a legitimate registrant. It is possible.
[0138] In addition, the content management system 100 stores the content data in the requester terminal 300. Depending on the verification result of the availability of the content data, the content data may be provided to the requester terminal 300. This allows the content management system 100 to prevent unauthorized use of content data. The content data can be provided to the requester terminal 300 that is least likely to be affected.
[0139] The content management system 100 also encrypts the content data to generate an encrypted content. The content data is provided to at least one of the requester terminal 300 and an external information processing system. This allows the requester to retrieve encrypted content data in a predetermined manner. The content data can be used after being decrypted.
[0140] In addition, the content management system 100 stores the content data in the requester terminal 300. Depending on the result of the verification of whether the encrypted content data can be used, the key information required for using the encrypted content data is The content data can be provided to the requester terminal 300. Obtaining key information for use and decrypting the encrypted content data using a predetermined method; The content data can be used.
[0141] As described above, the content management system 100 processes the content after a predetermined process. A token is issued based on the data, and a request is made from the requester terminal 300 that has acquired the token. The content data is provided to the requester terminal 300 after verifying whether the content data is available or not according to the request. Although the embodiment has been described, the content management system 100 is a content management system After authenticating the 100 itself (wallet authentication), the content data is processed as required. After issuing the token, the processed content data is provided to the requester terminal 300. (i.e., the content data that has been processed before the token is issued may be provided. In addition, the token may be rewritten due to a transfer of rights, etc. At that timing, the content management system 100 performs a predetermined processing (update) on the content data. The content data that has been subjected to the update processing is provided to the requester terminal 300. The method of processing for updating may be, for example, removing the existing processing and writing a new Either rewriting the content into new content or adding new content in addition to the existing processing This may also be the case.
[0142] Here, the description will be given on the assumption that the content management system 100 is configured to perform a predetermined processing process. However, the registrant terminal 200 may be configured to have a function for carrying out a predetermined processing process. In either case, if the content data is processed in a certain way, The predetermined processing is performed based on a public key (e.g., a public key corresponding to each registrant) that is associated with the registrant. It is possible to verify whether the process has been properly carried out.
[0143] Furthermore, as another configuration, the content management system 100 includes a registrant terminal 200, etc. The private key, public key, and common key (e.g., the private key used in a virtual currency wallet) of each user and a public key, or any Processes such as Diffie-Hellman key exchanges are generated and shared by content management systems. 100, and the requester terminal 300 (for example, the T The content data is encrypted using a common key stored in the EE or the like. As an example of this configuration, the content management system 100 may be a storage system. A specific example will be described in which the system 400 is also provided.
[0144] A registrant terminal of a registrant (e.g., a creator of the content) who initially owns the content data 200 transmits content data to the content management system 100 (the registrant (The content may be transmitted after authentication by the content management system 100.) 0 (particularly, the encryption unit 125) converts the received content data into a corresponding The content is encrypted with the registrant's public key and recorded (at this time, the unencrypted content data is also recorded). The content management system 100 (particularly, the token issuing unit 135) A token corresponding to the data is issued and provided to the blockchain system 500. When a registrant wants to use (for example, view) the content, the registrant terminal 200 From the content management system 100 (particularly, in response to processing by the encrypted content providing unit 130) The encrypted content data is obtained (if the registrant has passed the authentication of the content management system 100). The registrant can then use the encrypted content data by decrypting it with the registrant's private key (or later). (Playback in a TEE or other environment is also acceptable.)
[0145] The current user who currently owns the content (for example, the registered user who initially owns the content data) When a user (registerer) wants to sell a content, the current user registers the content in the content management system 100. By sending a sell request, the content will be available for sale, and other users will be able to purchase the content. When someone wants to buy the content (after the sale is completed), the public key of the current user is encrypted. The encrypted content data is deleted and the original content data is restored. The encrypted content data encrypted with the public key of the new owner (new user) is recorded. Then, a token corresponding to the new encrypted content data is generated (eg, updated).
[0146] In this way, when a new user wishes to use the content management system 100, The encrypted content data encrypted with the public key of the new user held at the time of purchase is The new user can then use the content by decrypting it with his or her own private key. do.
[0147] <Modification> Up to this point, the content data is encrypted with the registrant's public key and recorded. Although an example of decrypting content data encrypted with the private key of the corresponding registrant has been explained, The content data is encrypted with a predetermined common key, and this common key is then encrypted with the owner's public key. The owner decrypts the encrypted common key with his / her own private key, and uses this common key to The encrypted content data may be decoded and used. When content is transferred, the content data is encrypted with a specified common key. The common key is encrypted with the public key of the transferee, and the transferee uses its own private key to The recipient uses the common key to decrypt the encrypted content data. A specific example of the operation of this embodiment will be described with reference to FIG. cormorant.
[0148] First, the registrant completes the content, and the registrant terminal generates the content data (S 701). The content management system 100 (e.g., the content acquisition unit 110) Based on the operation of the user terminal 200, for example, content data is acquired from the user terminal 200. The content management system 100 (for example, the processing unit 1 15) performs a prescribed processing on the acquired content data (for example, the registrant is the right holder) The content management system 100 (e.g., For example, the encryption unit 125 encrypts the processed content data with a predetermined first common key (user The first encrypted content data is generated by encrypting the first encrypted content data with a common key prepared for each content. The content management system 100 (for example, the encryption unit 125) uses the The first common key is encrypted with the public key of the registrant to generate a first encrypted common key (S704). The content management system 100 (for example, the encrypted content providing unit 130) The encrypted content data is sent to the content management system 100 (for example, ) provide the first encryption common key to the storage system 400 (note that The common encryption key may be provided to the registrant individually (S705). The system 100 (e.g., the token issuing unit 135) issues a token corresponding to the content data. The token is issued (S706) and provided (deployed) to the blockchain system 500 (S The registrant terminal 200 receives the first encrypted content data from the storage system 400. The first encrypted common key is decrypted with the registrant's private key, and The first encrypted content data is decrypted with the obtained common key, making the content data usable.
[0149] When content is transferred, the transferee becomes the requester. Transferee (requester) The user acquires the token through the transferee terminal (the requester terminal 300) (S708). The content management system 100 (for example, the provision request acquisition unit 140) receives a token from the transferee terminal. A request for providing content data based on the content is obtained (S709). The management system 100 (for example, the provision request acquisition unit 140) receives the public information of the transferee as a provision request. The content management system 100 (for example, the usage verification unit 1 45) provides a content provision service in the transferee terminal in response to a provision request obtained from the transferee terminal. The availability of the data is verified (S710), and if the data is available, the content management system 10 0 is the original stored content data that has been processed in a specific way (for example, if the transferee is the rights holder, At this time, the content management system 100 performs a processing process to determine whether the content is a transferee or not. (S711) The content data is encrypted with a predetermined second common key (a common key prepared for each user or each content). and generating second encrypted content data using the public key of the transferee from the transferee terminal. The second common key is encrypted to generate a second encrypted common key (S712). The encrypted content data and the second encrypted common key are provided to the storage system 400 (Note that The encrypted common key may be provided to the transferee individually (S713). The second common key may be the same common key or may be a different common key. The user terminal transmits the second encrypted content data and the second encrypted common key to the storage system 40. The transferee terminal acquires the second encryption code from the storage system 400 (S714). The second encrypted common key is then decrypted using the transferee's private key. The second encrypted content data is decrypted with the decrypted second common key to obtain the content data. In this step, the content data can be used at the transferee terminal. Instead, the content management system authenticates the transferee (ID , password, etc.
[0150] As mentioned above, the processing of the content data by the current owner (registerer or transferee) Since the registration is protected by a watermark (e.g., a digital watermark containing the registrant's ID or the transferee's ID), if Even if content data is leaked in any way, the electronic By checking the child watermark, it is possible to identify the source of the leak. The processing may be performed by the content management system 100, or by the registrant terminal 200 or For example, the public key or private key of the registrant or the transferee may be processed by the transferee terminal. It is also possible to use it to add a "digital watermark" to the content through encryption (signature) processing. In addition, the operation of processing the content data has been explained, but this can be omitted. be.
[0151] In addition, the content management system 100 detects that the token has been updated due to the transfer. , deleting the encrypted content data and the encrypted common key of the recipient of the storage system 400 In addition, the token may contain the public key of the grantor or its link address. If the token is included in the transfer, the content management system 100 must notify the user that the token has been updated. detects the content, encrypts it with a predetermined common key, and converts the predetermined common key into the public key of the transferee. and stores the encrypted content and the encrypted common key in the storage system 400. Then, at any timing, the transferee terminal may transfer the encrypted content and the encrypted common key. may be obtained from the storage system 400 and decrypted using the recipient's private key. , the content management system 100 (for example, the encrypted content providing unit 130, the encrypted common The key providing unit) directly transmits the encrypted The content data and the encryption symmetric key may be provided.
[0152] In addition, the previous owner (old user) has previously owned the content in the content management system 100. Even if the user requests the provision of the content data, the content management system 100 does not provide the content data. Even if the encrypted content data is obtained, the new user's private key is not available. Since the content cannot be decrypted, it is not possible to use the content. The old encrypted content data encrypted with the old user's public key provided by the server is TE E, etc., was provided to old users at a point in time, so at this point, old users The old encrypted content data encrypted with the user's public key cannot be accessed. It is also not possible to use content that uses old encrypted content data.
[0153] In addition, the content management system 100 includes a storage system 400. In order to facilitate the description of the configuration of the content management system 100, which has been described above, In a configuration in which the content management system 100 also includes a storage system 400, Although there is no explanation of the configuration for performing the predetermined processing operations such as watermarking, The processing system 100 may perform the predetermined processing, or may be a content management system. The storage system 400 may be separated from the system 100. Although the public key cryptosystem has been described, a common key system may be used. The content management system 100 then uses the common key to The content data may be encrypted, or the content management system 100 may The content data is encrypted using a common key, on the premise that the common key for each content is held in advance. The configuration may be also possible.
[0154] The modified example of the present invention has been described above. A token corresponding to the content data that was accepted for registration based on the last 200 operation is issued. The registered content data is encrypted with a first common key, and the first common key is converted to the public key of the registrant. Providing content data based on the token obtained from the requester terminal 300 after encryption In response to a request, it is possible to verify whether the content data is available at the requester terminal 300. This allows the content management system 100 to prevent unauthorized use of content data. can be avoided.
[0155] In addition, the content management system 100 may automatically determine whether or not the registered content is available depending on the result of the usage verification. The data can be encrypted with a second common key, and the second common key can be encrypted with the requester's public key. This allows the previous owner of the content (old user) to circumvent the encrypted content data. Even if they obtain the data, they do not have the new user's private key and cannot decrypt it. Since the content cannot be used, the content management system 100 This can prevent unauthorized use of data.
[0156] In addition, the content management system 100 stores the second encrypted content data and the second encrypted The common key is provided to at least one of the requester terminal 300 and an external information processing system. This allows the requester to receive the second encrypted content data and the second encrypted share. The registered content data can be used by using the shared key.
[0157] In addition, the content management system 100 uses the private key of the registrant or the private key of the requester to In this way, the content management system 100 can: For example, to identify the rights holder (e.g., registrant, assignee) of registered content data can be done.
[0158] In addition, the content management system 100 manages the content based on the operation of the registrant terminal 200. The content data is registered, the registered content data is encrypted with the first common key, and the first common key is registered. The first encrypted content data and the first encrypted common key are encrypted by the registrant's public key. It can be provided to at least one of the terminal 200 and the storage system 400. In this way, the content management system 100 can prevent unauthorized use of content data. It is possible.
[0159] In addition, the content management system 100 manages the content based on the operation of the registrant terminal 200. The content data is registered, the registered content data is encrypted with the second common key, and the second common key is registered. The second encrypted content data and the second encrypted common key are encrypted with the public key of the recorder, for example. At least one of the transferee terminal (requester terminal 300) and the storage system 400 , can be provided. This allows the previous owner (old user) of the content to, Even if the encrypted content data is obtained, the new user does not have the private key and cannot decrypt it. Content management system 1 00 can prevent unauthorized use of content data.
[0160] It should be noted that the present embodiment is provided to facilitate understanding of the present invention and does not limit the present invention. The present invention is not intended to be interpreted as being limited to the above-mentioned embodiments, and may be modified or improved without departing from the spirit and scope of the present invention. and equivalents thereof are also included in the present invention. [Explanation of symbols]
[0161] 100 Content management system, 105 Storage unit, 110 Content acquisition unit, 115 Processing unit, 120 content registration unit, 125 encryption unit, 130 encrypted content token providing unit, 135 token issuing unit, 140 provision request acquisition unit, 145 usage verification unit, 50 content providing unit, 155 key providing unit, 200 registrant terminal, 300 requester terminal , 400 storage systems, 500 blockchain systems
Claims
1. A content acquisition unit acquires the content data based on the operation of the user's terminal by the user who registers the content data, Based on the acquired content data, a content registration unit accepts registration of the content data, An encryption unit that generates encrypted content data by encrypting the registered content data with a predetermined common key, and generates an encrypted common key by encrypting the predetermined common key with the public key of the requester who received the content data, which is different from the registrant, An encrypted content providing unit that provides the encrypted content data to at least one of the requester's requester terminal and an external information processing system, An encryption key provisioning unit that provides the aforementioned encryption key to at least one of the requester terminal and an external information processing system, A content management system equipped with the following features.
2. A token issuing unit that issues tokens corresponding to the registered content data based on the registered content data, A usage verification unit that verifies whether the content data is available on the requesting terminal in response to a request for provision of the content data based on the token obtained from the requesting terminal, The content management system according to claim 1, further comprising:
3. The content management system according to claim 1 or 2, further comprising a processing unit that performs a predetermined processing on the content data, using the private key or public key of the registrant or the transferee, to indicate that the content data is registered based on the registrant's operation or that the transferee has received the content data.
4. The content management system according to claim 3, wherein the predetermined processing includes a processing that applies a digital watermark to the content data that can identify the registrant or the transferee.
5. The processing unit performs the predetermined processing using the registered user's private key or public key. The content registration unit accepts registration of content data based on the content data that has undergone the predetermined processing. The content management system according to claim 3.
6. Computers Based on the operation of the registrant's terminal when registering content data, the content data is acquired, Based on the acquired content data, registration of the content data will be accepted. The registered content data is encrypted with a predetermined shared key to generate encrypted content data, and the predetermined shared key is encrypted with the public key of the requester who received the content data, which is different from the registrant, to generate an encrypted shared key. The encrypted content data is provided to at least one of the requester's requester terminal and an external information processing system. The encryption common key is provided to at least one of the requester terminal and an external information processing system. Content management methods.
7. On the computer, A content acquisition unit acquires the content data based on the operation of the user's terminal by the user who registers the content data, Based on the acquired content data, a content registration unit accepts registration of the content data, An encryption unit that generates encrypted content data by encrypting the registered content data with a predetermined common key, and generates an encrypted common key by encrypting the predetermined common key with the public key of the requester who received the content data, which is different from the registrant, An encrypted content providing unit that provides the encrypted content data to at least one of the requester's requester terminal and an external information processing system, An encryption key provisioning unit that provides the aforementioned encryption key to at least one of the requester terminal and an external information processing system, A content management program designed to achieve this.