Use right verification system, use right verification method therefor, and program
The system uses biometric information to generate and verify digital signatures, addressing unauthorized use in digital content trading by ensuring only legitimate users can access content, thus preventing impersonation and fraud.
Patent Information
- Application Number
- JP2024088861
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-31
- Publication Date
- 2025-12-11
AI Technical Summary
In digital content trading systems, unauthorized use of content usage rights can occur if the private key falls into the wrong hands, allowing impersonation and fraudulent use.
A system that uses biometric information to generate digital signature information, which is then verified using a public key, ensuring that only the legitimate user can access the content, thereby preventing unauthorized use.
This approach reliably prevents impersonation and fraudulent use of content by ensuring that only the rightful user can access and use the content, even if the private key is compromised.
Smart Images

Figure 2025181096000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a system for verifying a right of use, a method for verifying a right of use, and a program therefor. [Background technology]
[0002] In a digital content trading system, for example, content usage right information is issued to a device of a user who purchases and uses the content. The user's device can use the content based on the usage right information. To prevent such unauthorized use of usage right information, a system using a public key and a private key is known (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Special Publication No. 2008-529341 Summary of the Invention [Problem to be solved by the invention]
[0004] However, if the private key falls into the hands of another person, there is a risk that that person may pose as the user and make unauthorized use of the usage right information.
[0005] An object of the present disclosure is to provide a system for verifying usage rights, a method for verifying usage rights, and a program that solves any of the above-mentioned problems. [Means for solving the problem]
[0006] In order to achieve the above object, one aspect of the present disclosure is to a content use means for acquiring biometric information of a user, storing content usage right information, and using the content; a usage right presentation proxy means for storing key parameters in association with the biometric information of a user; a content management means for storing a public key for digital signature information of a user generated based on the biometric information of the user; Equipped with the content use means transmits the acquired biometric information of the user and the usage right information of the content to the usage right presentation agent means; the usage right presentation proxy means generates digital signature information of the user based on the transmitted biometric information of the user and a key parameter corresponding to the biometric information, and transmits signed usage right information obtained by attaching the digital signature information to the usage right information to a content management means; the content management means verifies the digital signature information of the user based on the signed usage right information, using the corresponding public key; Usage Rights Verification System is. In order to achieve the above object, one aspect of the present disclosure is to a content use means for acquiring biometric information of a user, storing content usage right information, and using the content; a usage right presentation proxy means for storing key parameters in association with the biometric information of a user; a content management means for storing a public key for digital signature information of a user generated based on biometric information of the user, a step in which the content use means transmits the acquired biometric information of the user and the usage right information of the content to the usage right presentation agent means; the usage right presentation proxy means generates digital signature information of the user based on the transmitted biometric information of the user and a key parameter corresponding to the biometric information, and transmits signed usage right information obtained by attaching the digital signature information to the usage right information to a content management means; the content management means verifies the digital signature information of the user based on the signed usage right information using the corresponding public key; A method for verifying the right of use of a system for verifying the right of use, including: is. In order to achieve the above object, one aspect of the present disclosure is to a content use means for acquiring biometric information of a user, storing content usage right information, and using the content; a usage right presentation proxy means for storing key parameters in association with the biometric information of a user; a content management means for storing a public key for digital signature information of a user generated based on the biometric information of the user, a process in which the content use means transmits the acquired biometric information of the user and the usage right information of the content to the usage right presentation agent means; a process in which the usage right presentation proxy means generates digital signature information of the user based on the transmitted biometric information of the user and key parameters corresponding to the biometric information, and transmits signed usage right information obtained by attaching the digital signature information to the usage right information to a content management means; a process in which the content management means verifies the digital signature information of the user based on the signed usage right information using the corresponding public key; A program for a system for verifying the right of use that causes a computer to execute the above. is. [Effects of the Invention]
[0007] According to the present disclosure, it is possible to provide a usage right verification system, a usage right verification method, and a program that solve any of the above-mentioned problems. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a diagram illustrating an example of a digital content trading system according to the present disclosure. [Figure 2] 1 is a diagram illustrating an example of the configuration of a usage right verification system according to the present disclosure. [Figure 3] 2 is a diagram illustrating an example of the hardware configuration of a content management device, a usage right presentation proxy device, and a content usage device. FIG. [Figure 4]1 is a diagram illustrating an example of the configuration of a usage right verification system according to the present disclosure. [Figure 5] FIG. 1 is a flowchart illustrating an example of a flow of a method for verifying usage rights according to the present disclosure. [Figure 6] 1 is a diagram illustrating an example of the configuration of a usage right verification system according to the present disclosure. [Figure 7] FIG. 1 is a diagram illustrating an example of a configuration of a decision-making device. [Figure 8] 1 is a diagram illustrating an example of the configuration of a usage right verification system according to the present disclosure. [Figure 9] FIG. 1 is a flowchart illustrating an example of a flow of a method for verifying usage rights according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0009] Embodiment 1 In a digital content trading system 100, for example, as shown in Fig. 1, a device 2 of a content creator and a store (hereinafter referred to as a content management device 2) issues content usage right information to a device 3 of a user who purchases and uses the content (hereinafter referred to as a content usage device 3). The content usage device 3 presents the electronic usage right information to each content management device 2 that handles the same content, thereby enabling the content to be used via an application or the like.
[0010] The content usage device 3 includes not only a device owned by an individual but also a device shared with others. The content includes, for example, electronic books such as comics, novels, and magazines, videos, digital art, games, and music.
[0011] The usage right verification system according to this embodiment is a system for more reliably preventing unauthorized use of content usage right information in the digital content trading system 100 described above.
[0012] For this reason, the usage right verification system according to this embodiment is characterized in that it assigns the user's digital signature information, which is generated based on the user's biometric information, to the usage right information of the content purchased by the user. Furthermore, as shown in Fig. 2, the usage right verification system 1 according to this embodiment is characterized in that it has a usage right presentation agent's device 4 (hereinafter referred to as usage right presentation agent device 4) separate from the content usage device 3 perform the generation of the user's digital signature information and the presentation of the usage right information.
[0013] As shown in FIG. 2, the usage right verification system 1 includes a content management device 2, a content usage device 3, and a usage right presentation proxy device 4.
[0014] The content usage device 3 is a specific example of a content usage means. The content usage device 3 transmits to the usage right presentation proxy device 4 the biometric information of the user acquired from the user and usage right information of the content.
[0015] The usage right presentation proxy device 4 is a specific example of usage right presentation proxy means. The usage right presentation proxy device 4 generates digital signature information of the user based on the user's biometric information transmitted from the content usage device 3 and key parameters corresponding to the biometric information. The key parameters corresponding to the biometric information are generated based on the user's generation information. The usage right presentation proxy device 4 transmits signed usage right information, in which the generated digital signature information is added to the usage right information, to the content management device 2.
[0016] The content management device 2 is a specific example of content management means. Based on the signed usage right information, the content management device 2 verifies the user's digital signature information using a corresponding public key. The corresponding public key is generated in advance based on the user's biometric information. If the content management device 2 successfully verifies the user's digital signature information, it transmits the content corresponding to the usage right information to the content usage device 3.
[0017] In this way, if the biometric information used as the basis for the key parameters when generating the user's signature is the same as the biometric information of the user who generated the signature, a valid digital signature will be generated. The digital signature is then verified using a public key generated based on the same biometric information.
[0018] In other words, whether or not a user is a legitimate holder of the content usage rights can be determined more reliably by whether or not the digital signature and the corresponding public key are generated based on the same biometric information. This more reliably prevents so-called spoofing, in which the presenter of the usage rights is replaced by someone other than the user himself / herself. In other words, it more reliably prevents fraudulent use of the content usage rights.
[0019] The content management device 2, the content usage device 3, and the usage right presentation agent device 4 may be wirelessly connected to each other for communication, for example, via a wireless LAN (Local Area Network), Wifi (registered trademark), or the like.
[0020] The content management device 2, the content usage device 3, and the usage right presentation agent device 4 may each have the hardware configuration of a typical computer, as shown in FIG. 3, including a processor 11 such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit), an internal memory 12 such as a RAM (Random Access Memory) or a ROM (Read Only Memory), a storage device 13 such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive), an input / output I / F 14 for connecting peripheral devices such as a display, and a communication I / F 15 for communicating with devices external to the device.
[0021] The content management device 2 and the usage right presentation proxy device 4 may each be configured as a server device. The content management device 2 and the usage right presentation proxy device 4 may also be configured integrally. The content usage device 3 may also be configured as a mobile terminal such as a smartphone, a PC (Personal Computer), a tablet terminal, or the like.
[0022] Next, a detailed description will be given of the configuration and functions of the content management device 2. As shown in Fig. 4, the content management device 2 has a usage right verification unit 21, a usage right validity confirmation unit 22, a usage right invalidation unit 23, a content providing unit 24, a usage right update unit 25, a content storage unit 26, a public key storage unit 27, and a valid usage right list storage unit 28.
[0023] The usage right verification unit 21 verifies the digital signature information attached to the usage right information using the public key stored in the public key storage unit 27 .
[0024] The usage right validity confirmation unit 22 confirms the validity of the usage right information of the content based on the list information in the valid usage right list storage unit 28.
[0025] The usage right invalidation unit 23 invalidates usage right information by deleting the usage right information from the list information of the valid usage right list storage unit 28, which will be described later.
[0026] The content providing unit 24 presents the content stored in the content storage unit 26 by transmitting it to the usage right presentation proxy device 4.
[0027] The usage right update unit 25 updates the content of the usage right information in accordance with the user's usage status. For example, the usage right update unit 25 updates the content of the usage right by deleting the user's digital signature information and the digital signature information of the content management device 2 from the usage right information.
[0028] The content storage unit 26 stores content created by a content creator such as an author in association with its usage right information. The usage right information is pre-assigned the digital signature information of the content creator. Furthermore, the usage right information is pre-assigned the digital signature information of the content management device 2.
[0029] The public key storage unit 27 stores public keys for the user's digital signature information, the content management device 2's digital signature information, and the content creator's digital signature information. The public key storage unit 27 may store public key information (such as a link) instead of the public key. The public key storage unit 27 may acquire the public key from a cloud or the like based on the public key information.
[0030] The public key for the user's digital signature information is generated in advance based on the user's biometric information. Either the content usage device 3 or the usage right presentation agent device 4 may generate the public key.
[0031] The valid usage rights list storage unit 28 stores list information that lists the usage rights information of valid content.
[0032] Next, a detailed description will be given of the configuration and functions of the usage right presentation proxy device 4. As shown in Fig. 4, the usage right presentation proxy device 4 has a biometric information acquisition unit 41, a usage right acquisition unit 42, a signature generation unit 43, a usage right presentation unit 44, and a key parameter storage unit 45.
[0033] The biometric information acquisition unit 41 acquires biometric information of the user from the content usage device 3. The usage right acquisition unit 42 acquires usage right information from the content usage device 3.
[0034] The signature generation unit 43 generates digital signature information of the user based on the biometric information acquired from the content usage device 3 and the key parameters stored in the key parameter storage unit and corresponding to the biometric information. The usage right presentation unit 44 presents the usage right information to the content management device 2.
[0035] The key parameter storage unit 45 stores key parameters. The key parameters are generated in advance based on the user's biometric information. Either the content usage device 3 or the usage right presentation proxy device 4 may generate the key parameters.
[0036] Next, a detailed description will be given of the configuration and functions of the content usage device 3. As shown in Fig. 4, the content usage device 3 has a biometric information acquisition unit 31, a usage right presentation unit 32, a content usage unit 33, and a usage right storage unit 34.
[0037] The biometric information acquisition unit 31 acquires biometric information of the user based on, for example, an image of the user acquired by a camera, the user's voice acquired by a microphone, etc. The biometric information of the user includes, for example, information on the user's face, iris, fingerprints, veins, voiceprint, palmprint, ears, etc.
[0038] The usage right presenting unit 32 presents the usage right information stored in the usage right storage unit 34 by transmitting it to the usage right presentation proxy device 4.
[0039] The content usage unit 33 uses the content transmitted from the usage right presentation proxy device 4. In this embodiment, "using the content" means that the content usage unit 33 plays the content transmitted from the usage right presentation proxy device 4 at any time while receiving it, for example, by streaming, without storing it in the content usage device 3. This makes it possible to more reliably prevent the unauthorized distribution of content.
[0040] The usage right storage unit 34 stores, for example, usage right information of content purchased by a user from the content management device 2, and updated usage right information, which will be described later.
[0041] Next, an example of a method for verifying the right to use by the usage right verification system 1 according to the present embodiment will be described with reference to FIG.
[0042] The usage right presentation unit 32 of the content usage device 3 transmits the user's biometric information acquired by the biometric information acquisition unit 31 and the usage right information stored in the usage right storage unit 34 to the usage right presentation proxy device 4 (step S101).
[0043] The signature generation unit 43 of the usage right presentation proxy device 4 generates digital signature information of the user based on the biometric information transmitted from the content usage device 3 and the key parameters corresponding to the biometric information stored in the key parameter storage unit 45. The usage right presentation unit 32 of the usage right presentation proxy device 4 transmits signed usage right information, in which the generated digital signature information of the user is attached to the usage right information, to the content management device 2 (step S102).
[0044] The usage right verification unit 21 of the content management device 2 verifies the user's digital signature information included in the signed usage right information from the usage right presentation agent device 4 using the public key stored in the public key memory unit 27, thereby determining whether the user's signature is valid (step S103).
[0045] If the usage right verification unit 21 of the content management device 2 succeeds in verifying the user's digital signature information and determines that the user's signature is valid (YES in step S103), it performs the following determination process (step S104). On the other hand, if the usage right verification unit 21 fails to verify the user's digital signature information and determines that the user's signature is invalid (NO in step S103), it ends this process.
[0046] The usage right verification unit 21 of the content management device 2 verifies the digital signature information of the content management device 2 included in the signed usage right information from the usage right presentation agent device 4 using the public key stored in the public key memory unit 27, thereby determining whether the signature of the content management device 2 is legitimate (step S104).
[0047] If the usage right verification unit 21 of the content management device 2 succeeds in verifying the digital signature information of the content management device 2 and determines that the signature of the content management device 2 is valid (YES in step S104), it performs the following judgment process (step S105). On the other hand, if the usage right verification unit 21 fails to verify the digital signature information of the content management device 2 and determines that the signature of the content management device 2 is invalid (NO in step S104), it ends this process.
[0048] The usage right verification unit 21 of the content management device 2 verifies the digital signature information of the content creator included in the signed usage right information from the usage right presentation agent device 4 using the public key stored in the public key memory unit 27, thereby determining whether the signature of the content creator is legitimate (step S105).
[0049] If the usage right verification unit 21 of the content management device 2 succeeds in verifying the digital signature information of the content creator and determines that the signature of the content creator is valid (YES in step S105), it performs the following determination process (step S106). On the other hand, if the usage right verification unit 21 fails to verify the digital signature information of the content creator and determines that the signature of the content creator is invalid (NO in step S105), it ends this process.
[0050] The usage right validity confirmation unit 22 of the content management device 2 determines whether the signed usage right information is valid or not based on the list information in the valid usage right list storage unit 28 (step S106).
[0051] If the usage right validity confirmation unit 22 of the content management device 2 determines that the usage right of the signed usage right information is included in the list information of the valid usage right list storage unit 28 and that the usage right of the content is valid (YES in step S106), it performs the following processing (step S107).On the other hand, if the usage right validity confirmation unit 22 determines that the usage right of the signed usage right information is not included in the list information of the valid usage right list storage unit 28 and that the usage right of the content is not valid (NO in step S106), it ends this processing.
[0052] The usage right invalidation unit 23 of the content management device 2 invalidates the usage right by deleting the usage right of the signed usage right information from the list information of the valid usage right list storage unit 28 (step S107).
[0053] The content providing unit 24 of the content management device 2 transmits the content stored in the content storage unit 26 and associated with the signed usage right information to the usage right presentation proxy device 4 (step S108).
[0054] The usage right presentation proxy device 4 transfers the content transmitted from the content management device 2 to the content usage device 3 (step S109). This allows the user to use the content on the content usage device 3.
[0055] The content providing unit 24 of the content management device 2 may transmit the content associated with the signed usage right information directly to the content usage device 3 without going through the usage right presentation proxy device 4.
[0056] The usage right update unit 25 of the content management device 2 updates the contents of the usage right information to match the user's usage status by deleting the user's digital signature information and the digital signature information of the content management device 2 from the signed usage right information (step S110).
[0057] The content management device 2 adds digital signature information to the updated usage right information (hereinafter referred to as updated usage right information), and transmits the updated usage right information with the digital signature information to the usage right presentation proxy device 4 (step S111).
[0058] The usage right presentation proxy device 4 transfers the updated usage right information with the digital signature information transmitted from the content management device 2 to the content usage device 3 (step S112). The usage right storage unit 34 of the content usage device 3 stores the updated usage right information with the digital signature information transferred from the usage right presentation proxy device 4.
[0059] The content management device 2 may transmit the updated usage right information with the digital signature information directly to the content usage device 3 without going through the usage right presentation proxy device 4.
[0060] Furthermore, at least one of the determination processes from (Step S104) to (Step S105) may be omitted. Furthermore, the order of the determination processes from (Step S104) to (Step S105) may be arbitrary.
[0061] As described above, according to the usage right verification method of the usage right verification system 1 of this embodiment, the user's biometric information is used instead of a private key to verify the identity of the user with respect to the content usage right. This makes it possible to more reliably prevent impersonation due to the leakage of the private key. Furthermore, since only the user himself / herself can generate correct digital signature information, it is possible to more reliably prevent fraudulent transfer (resale, etc.) of the usage right. Furthermore, in the process of signing and presenting the usage right, there is no opportunity for the sender to be changed from the user himself / herself to someone else. This makes it possible to more reliably prevent transfer of the signed usage right and impersonation due to theft.
[0062] Embodiment 2 As shown in Fig. 6, the usage right verification system 50 according to this embodiment further includes a decision-making device 51 that makes decisions by majority vote among multiple decision-making units. The decision-making device 51 is a specific example of a decision-making means. The decision-making device 51 is configured as, for example, a decentralized autonomous organization (DAO).
[0063] The decision-making device 51 determines, by majority vote of multiple decision-making units, whether or not the usage right presentation agent device 6 may transmit (present) the signed usage right information to the content management device 2. This more reliably prevents the usage right presentation agent, etc. from leaking the signed usage right information to anyone other than the user.
[0064] 7, a decision-making device 51 has n (n≧3) decision-making units 52. Each decision-making unit 52 has a shared key storage unit 521 and a presentation permission / non-permission determination unit 522.
[0065] The key share storage unit 521 stores the key shares. For example, n key shares are generated from one decryption key, and each of the n key shares is stored in the key share storage unit 521 of each of the decision making units 52. The presentation permission determination unit 522 determines whether or not to transmit the signed usage right information.
[0066] When the presentation permission determining unit 522 of each decision making unit 52 determines that the presentation of the signed usage right information is "allowed," it transmits the shared key in the shared key storage unit 521 to the usage right presentation agent device 6 in response to a request from the usage right presentation agent device 6. The usage right presentation agent device 6 decrypts the encrypted key parameters based on the shared key transmitted from each decision making unit 52, as will be described later.
[0067] As shown in FIG. 8, the usage right presentation proxy device 6 according to this embodiment further includes an encryption / decryption key generation unit 61, a key parameter encryption / decryption unit 62, and a decryption key recovery unit 63 in addition to the above configuration.
[0068] The encryption / decryption key generation unit 61 generates an encryption key for encrypting key parameters required for generating digital signature information of a user. The encryption / decryption key generation unit 61 also generates a decryption key for decrypting the encrypted key parameters, and generates n key shares from the generated decryption key. The encryption / decryption key generation unit 61 transmits the generated n key shares to n decision making units 52, respectively.
[0069] The key parameter encryption / decryption unit 62 encrypts the key parameters using an encryption key, and decrypts the encrypted key parameters using a decryption key.
[0070] The decryption key recovery unit 63 recovers the decryption key based on the multiple key shares transmitted from the decision making unit 52. For example, when the decryption key recovery unit 63 obtains key shares indicating "OK" from m (m≦n) of the n decision making units 52, the decryption key recovery unit 63 recovers the decryption key using the key shares. The key parameter encryption / decryption unit 62 decrypts the encrypted key parameters in the key parameter storage unit 45 using the decryption key recovered by the decryption key recovery unit 63.
[0071] The signature generation unit 43 can generate digital signature information of the user based on the biometric information transmitted from the content usage device 3 and the decrypted key parameters. Then, the usage right presentation unit 32 can transmit signed usage right information, in which the generated digital signature information of the user is attached to the usage right information, to the content management device 2.
[0072] Next, an example of a method for verifying the right to use by the system for verifying the right to use according to the present embodiment will be described with reference to FIG.
[0073] The key parameter encrypting / decrypting unit 62 of the usage right presentation agent device 6 encrypts the key parameters in the key parameter storage unit using an encryption key. The key parameter encrypting / decrypting unit 62 generates n key shares from the decryption key. The key parameter encrypting / decrypting unit 62 transmits the generated n key shares to the n decision making units 52 of the decision making device 51, respectively, and stores one key share in each key share storage unit 521 (step S201).
[0074] The usage right presenting unit 32 of the content usage device 3 transmits the user's biometric information acquired by the biometric information acquiring unit 31 and the usage right information stored in the usage right storage unit 34 to the usage right presentation proxy device 6 (step S202).
[0075] The usage right presentation agent device 6 requests the key shares from the n decision making units 52 of the decision making device 51 (step S203).
[0076] The presentation permission determining unit 522 of each decision making unit 52 determines that presentation of the signed usage right information is "permitted" and judges whether to approve the request for the key share (step S204).
[0077] When each presentation permission determining unit 522 determines to accept the request for the key share (YES in step S204), it transmits the key share stored in the key share storage unit 521 to the usage right presentation proxy device 6 (step S205).
[0078] The decryption key recovery unit of the usage right presentation agent device 6 determines whether or not m (m≦n) key shares have been received (step S206).
[0079] If the decryption key recovery unit 63 determines that it has received m key shares (YES in step S206), it recovers the decryption key based on the received key shares. Then, the key parameter encryption / decryption unit 62 decrypts the encrypted key parameters in the key parameter storage unit 45 using the decryption key recovered by the decryption key recovery unit 63 (step S207).
[0080] The signature generation unit 43 of the usage right presentation proxy device 6 generates digital signature information of the user based on the biometric information transmitted from the content usage device 3 and the decrypted key parameters. The usage right presentation unit 32 of the usage right presentation proxy device 6 transmits signed usage right information, in which the generated digital signature information of the user is attached to the usage right information, to the content management device 2 (step S208).
[0081] In the subsequent processing, the same processing as that in (step S103) to (step S112) shown in Fig. 5 is executed. Therefore, the explanation in Fig. 5 is used and a detailed explanation is omitted here.
[0082] The above-described configuration of the decision-making device 51 is merely an example, and is not limited to this. Each decision-making unit 52 of the decision-making device 51 may be a physically separated device. Furthermore, the decision-making device 51 may have any configuration as long as it can determine whether or not to transmit the signed usage right information by majority vote of the multiple decision-making units 52.
[0083] Furthermore, the decision-making device 51 may also be provided in the content management device 2. In this case, the decision-making device 51 determines whether or not to receive signed usage right information from the usage right presentation agent device 6 by majority vote of multiple decision-making units 52. This makes it possible to more reliably prevent the usage right presentation agent or the like from leaking signed usage right information to anyone other than the user.
[0084] The present disclosure can also be realized by causing a processor to execute a computer program to perform the processes shown in FIG. 5 or FIG.
[0085] The program can be stored and supplied to a computer using various types of non-transitory computer readable media. Non-transitory computer readable media include various types of tangible storage media. Examples of non-transitory computer readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical recording media (e.g., magneto-optical disks), CD-ROMs (Read Only Memory), CD-Rs, CD-R / Ws, and semiconductor memories (e.g., mask ROMs, PROMs (Programmable ROMs), EPROMs (Erasable PROMs), flash ROMs, and RAMs (Random Access Memory)).
[0086] The program may be provided to the computer by various types of transitory computer-readable media. Examples of transitory computer-readable media include electrical signals, optical signals, and electromagnetic waves. The transitory computer-readable media can provide the program to the computer via a wired communication path such as an electrical wire or optical fiber, or via a wireless communication path.
[0087] Each component of the usage right verification system 1, 50 according to the above-described embodiment can be realized not only by a program, but also in part or in whole by dedicated hardware such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array).
[0088] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.
[0089] Each drawing is merely an example for describing one or more embodiments. Each drawing may relate not only to one particular embodiment, but also to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessary to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate.
[0090] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes. (Appendix 1) a content use means for acquiring biometric information of a user, storing content usage right information, and using the content; a usage right presentation proxy means for storing key parameters in association with the biometric information of a user; a content management means for storing a public key for digital signature information of a user generated based on the biometric information of the user; Equipped with the content use means transmits the acquired biometric information of the user and the usage right information of the content to the usage right presentation agent means; the usage right presentation proxy means generates digital signature information of the user based on the transmitted biometric information of the user and a key parameter corresponding to the biometric information, and transmits signed usage right information obtained by attaching the digital signature information to the usage right information to a content management means; the content management means verifies the digital signature information of the user based on the signed usage right information, using the corresponding public key; Right-to-use verification system. (Appendix 2) 10. The system for verifying usage rights according to claim 1, the content management means transmits the content corresponding to the usage right information to the content usage means when the verification of the digital signature information of the user is successful; Right-to-use verification system. (Appendix 3) 10. The system for verifying usage rights according to claim 1, a decision-making unit that decides whether or not the usage-right presentation proxy unit is permitted to transmit the signed usage-right information to the content management unit by majority vote of a plurality of decision-making units; Right-to-use verification system. (Appendix 4) 3. The system for verifying the right of use according to claim 3, the decision-making unit includes a shared key storage unit that stores the shared key, and a presentation permission determination unit that determines whether to transmit the signed usage right information; the presentation permission determination unit of each of the decision units transmits the shared key from the shared key storage unit to the usage right presentation proxy means in response to a request from the usage right presentation proxy means based on the result of the decision on whether to present the shared key; the use right presentation agent means restores a decryption key using the transmitted key share, decrypts encrypted key parameters using the restored decryption key, and generates digital signature information of the user based on the transmitted biometric information of the user and the decrypted key parameters. Right-to-use verification system. (Appendix 5) 10. The system for verifying usage rights according to claim 1, the content management means stores a public key for the user's digital signature information, a public key for the content management means' digital signature information, and a public key for the content creator's digital signature information; the content management means, based on the signed usage right information, performs a first verification of the user's digital signature information using the corresponding public key, a second verification of the content management means' digital signature information using the corresponding public key, and a third verification of the content creator's digital signature information using the corresponding public key, and transmits the content corresponding to the usage right information to the content usage means if the first verification, the second verification, and the third verification are successful. Right-to-use verification system. (Appendix 6) 10. The system for verifying usage rights according to claim 1, the content management means stores list information including valid content usage right information, and determines whether the usage right of the signed usage right information is valid based on the list information; Right-to-use verification system. (Appendix 7) 10. The system for verifying usage rights according to claim 1, the content use means receives and simultaneously plays back the content transmitted from the usage right presentation agent means without storing the content in the content use means; Right-to-use verification system. (Appendix 8) 10. The system for verifying usage rights according to claim 1, the content management means deletes the digital signature information of the user and the digital signature information of the content management means from the signed usage right information, updates the content of the signed usage right information, and transmits the updated usage right information to the content usage means, with the digital signature information added to the updated updated usage right information. Right-to-use verification system. (Appendix 9) a content use means for acquiring biometric information of a user, storing content usage right information, and using the content; a usage right presentation proxy means for storing key parameters in association with the biometric information of a user; a content management means for storing a public key for digital signature information of a user generated based on biometric information of the user, a step in which the content use means transmits the acquired biometric information of the user and the usage right information of the content to the usage right presentation agent means; the usage right presentation proxy means generates digital signature information of the user based on the transmitted biometric information of the user and a key parameter corresponding to the biometric information, and transmits signed usage right information obtained by attaching the digital signature information to the usage right information to a content management means; the content management means verifies the digital signature information of the user based on the signed usage right information using the corresponding public key; A method for verifying usage rights in a usage rights verification system, comprising: (Appendix 10) a content use means for acquiring biometric information of a user, storing content usage right information, and using the content; a usage right presentation proxy means for storing key parameters in association with the biometric information of a user; a content management means for storing a public key for digital signature information of a user generated based on the biometric information of the user, a process in which the content use means transmits the acquired biometric information of the user and the usage right information of the content to the usage right presentation agent means; a process in which the usage right presentation proxy means generates digital signature information of the user based on the transmitted biometric information of the user and key parameters corresponding to the biometric information, and transmits signed usage right information obtained by attaching the digital signature information to the usage right information to a content management means; a process in which the content management means verifies the digital signature information of the user based on the signed usage right information using the corresponding public key; A program for a usage rights verification system that causes a computer to execute the above.
[0091] Some or all of the elements (e.g., configurations and functions) described in Supplementary Note 2 to Supplementary Note 8 that are dependent on Supplementary Note 1 {e.g., device} may also be dependent on Supplementary Note 9 {e.g., method} and Supplementary Note 10 {e.g., program} in the same dependency relationship as Supplementary Note 2 to Supplementary Note 8. Some or all of the elements described in any Supplementary Note may be applied to various hardware, software, recording means for recording software, systems, and methods. [Explanation of symbols]
[0092] 1. Usage rights verification system 2 Content Management Device 3 Content Usage Device 4. Usage rights presentation agent device 6. Usage rights presentation agent device 21 Usage Rights Verification Department 22. Usage Rights Validity Verification Department 23. Right of Use Revocation Section 24 Contents Provider 25. License Renewal Department 26 Content storage unit 27 Public key storage unit 28 Effective use rights list storage unit 31 Biometric information acquisition unit 32 Usage Rights Presentation Section 33 Content Usage Department 34 Usage rights memory unit 41 Biometric information acquisition unit 42 User Rights Acquisition Department 43 Signature generation section 44 Usage Rights Presentation Section 45 Key parameter storage unit 50 Right to Use Verification System 51 Decision-making device 52 Decision Making Department 61 Encryption / Decryption Key Generation Unit 62 Key parameter encryption / decryption unit 63 Decryption key recovery unit 100 Digital Content Trading System 521 Distributed key storage unit 521 Each distributed key storage unit 521 Distributed key storage unit 522 Presentation propriety decision unit
Claims
1. a content use means for acquiring biometric information of a user, storing content usage right information, and using the content; a usage right presentation proxy means for storing key parameters in association with the biometric information of a user; a content management means for storing a public key for digital signature information of a user generated based on the biometric information of the user; Equipped with the content use means transmits the acquired biometric information of the user and the usage right information of the content to the usage right presentation agent means; the usage right presentation proxy means generates digital signature information of the user based on the transmitted biometric information of the user and a key parameter corresponding to the biometric information, and transmits signed usage right information obtained by attaching the digital signature information to the usage right information to a content management means; the content management means verifies the digital signature information of the user based on the signed usage right information, using the corresponding public key; Right-to-use verification system.
2. 2. The system for verifying usage rights according to claim 1, the content management means transmits the content corresponding to the usage right information to the content usage means when the verification of the digital signature information of the user is successful; Right-to-use verification system.
3. 2. The system for verifying usage rights according to claim 1, a decision-making unit that decides whether or not the usage-right presentation proxy unit is permitted to transmit the signed usage-right information to the content management unit by majority vote of a plurality of decision-making units; Right-to-use verification system.
4. 4. The system for verifying the right of use according to claim 3, the decision-making unit includes a shared key storage unit that stores the shared key, and a presentation permission determination unit that determines whether to transmit the signed usage right information; the presentation permission determination unit of each of the decision units transmits the shared key from the shared key storage unit to the usage right presentation proxy means in response to a request from the usage right presentation proxy means based on the result of the decision on whether to present the shared key; the use right presentation agent means restores a decryption key using the transmitted key share, decrypts encrypted key parameters using the restored decryption key, and generates digital signature information of the user based on the transmitted biometric information of the user and the decrypted key parameters. Right-to-use verification system.
5. 2. The system for verifying usage rights according to claim 1, the content management means stores a public key for the user's digital signature information, a public key for the content management means' digital signature information, and a public key for the content creator's digital signature information; the content management means, based on the signed usage right information, performs a first verification of the user's digital signature information using the corresponding public key, a second verification of the content management means' digital signature information using the corresponding public key, and a third verification of the content creator's digital signature information using the corresponding public key, and transmits the content corresponding to the usage right information to the content usage means if the first verification, the second verification, and the third verification are successful. Right-to-use verification system.
6. 2. The system for verifying usage rights according to claim 1, the content management means stores list information including valid content usage right information, and determines whether the usage right of the signed usage right information is valid based on the list information; Right-to-use verification system.
7. 2. The system for verifying usage rights according to claim 1, the content use means receives and simultaneously plays back the content transmitted from the usage right presentation agent means without storing the content in the content use means; Right-to-use verification system.
8. 2. The system for verifying usage rights according to claim 1, the content management means deletes the digital signature information of the user and the digital signature information of the content management means from the signed usage right information, updates the content of the signed usage right information, and transmits the updated usage right information to the content usage means, with the digital signature information added to the updated updated usage right information. Right-to-use verification system.
9. a content use means for acquiring biometric information of a user, storing content usage right information, and using the content; a usage right presentation proxy means for storing key parameters in association with the biometric information of a user; a content management means for storing a public key for digital signature information of a user generated based on biometric information of the user, a step in which the content use means transmits the acquired biometric information of the user and the usage right information of the content to the usage right presentation agent means; the usage right presentation proxy means generates digital signature information of the user based on the transmitted biometric information of the user and a key parameter corresponding to the biometric information, and transmits signed usage right information obtained by attaching the digital signature information to the usage right information to a content management means; the content management means verifies the digital signature information of the user based on the signed usage right information using the corresponding public key; A method for verifying usage rights in a usage rights verification system, comprising:
10. a content use means for acquiring biometric information of a user, storing content usage right information, and using the content; a usage right presentation proxy means for storing key parameters in association with the biometric information of a user; a content management means for storing a public key for digital signature information of a user generated based on the biometric information of the user, a process in which the content use means transmits the acquired biometric information of the user and the usage right information of the content to the usage right presentation agent means; a process in which the usage right presentation proxy means generates digital signature information of the user based on the transmitted biometric information of the user and key parameters corresponding to the biometric information, and transmits signed usage right information obtained by attaching the digital signature information to the usage right information to a content management means; a process in which the content management means verifies the digital signature information of the user based on the signed usage right information using the corresponding public key; A program for a usage rights verification system that causes a computer to execute the above.
Citation Information
Patent Citations
Private and Controlled Ownership Sharing
JP2008529341A